mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-28 23:51:26 +02:00
1.6 KiB
1.6 KiB
CVE-2020-14966
Description
An issue was discovered in the jsrsasign package through 8.0.18 for Node.js. It allows a malleability in ECDSA signatures by not checking overflows in the length of a sequence and '0' characters appended or prepended to an integer. The modified signatures are verified as valid. This could have a security-relevant impact if an application relied on a single canonical signature.
POC
Reference
Github
- https://github.com/ARPSyndicate/cvemon
- https://github.com/KarthickSivalingam/jsrsasign-github
- https://github.com/Live-Hack-CVE/CVE-2020-14966
- https://github.com/Olaf0257/certificate-decode
- https://github.com/andrzejm57/certificate-decode
- https://github.com/andrzejm57/certificate-decode-javascript
- https://github.com/astreiten/jsrsasign-mod
- https://github.com/coachaac/jsrsasign-npm
- https://github.com/colaf57/certificate-decode-javascript
- https://github.com/devstar57/certificate-decode
- https://github.com/devstar57/certificate-decode-javascript
- https://github.com/diotoborg/laudantium-itaque-esse
- https://github.com/ericxuan57/certificate-decode-javascript
- https://github.com/f1stnpm2/nobis-minima-odio
- https://github.com/firanorg/et-non-error
- https://github.com/kjur/jsrsasign
- https://github.com/zibuthe7j11/repellat-sapiente-quas