7.5
CVSSv3

CVE-2019-14853

Published: 26/11/2019 Updated: 17/12/2019
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

It exists that python-ecdsa incorrectly handled certain signatures. A remote attacker could possibly use this issue to cause python-ecdsa to generate unexpected exceptions, resulting in a denial of service. (CVE-2019-14853)

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

python-ecdsa project python-ecdsa

Vendor Advisories

Several security issues were fixed in python-ecdsa ...
It was discovered that python-ecdsa, a cryptographic signature library for Python, incorrectly handled certain signatures A remote attacker could use this issue to cause python-ecdsa to either not warn about incorrect signatures, or generate exceptions resulting in a denial-of-service For the oldstable distribution (stretch), these problems have ...
An error-handling flaw was found in python-ecdsa before version 0133 During signature decoding, malformed DER signatures could raise unexpected exceptions (or no exceptions at all), which could lead to a denial of service (CVE-2019-14853) A flaw was found in all python-ecdsa versions before 0133, where it did not correctly verify whether sign ...