Executive brief
python-ecdsa is a widely-used cryptographic library for handling ECDSA (Elliptic Curve Digital Signature Algorithm) signatures in Python applications. A vulnerability in signature decoding can cause unexpected exceptions that lead to denial of service, disrupting applications that rely on this library for cryptographic operations. This affects all versions prior to 0.13.3.
Technical details
The vulnerability exists in the signature decoding logic of python-ecdsa (versions prior to 0.13.3), where malformed or invalid signature input triggers unexpected and undocumented exceptions rather than being handled gracefully. An attacker can craft malformed ECDSA signatures that, when processed by an application using the library, cause the application to raise exceptions and potentially crash. The attack is triggered when an application attempts to verify or decode a signature; no authentication is required. The fix is available in version 0.13.3 and later.
Affected products
- python-ecdsa ecdsa before 0.13.3
Timeline
- 2019-10-04: disclosed
- 2019-10-07: patched: Version 0.13.3 released
- 2019-12-02: advisory
- 2020-06-16: other: Advisory withdrawn as duplicate of GHSA-pwfw-mgfj-7g3g