Junglewise Threat Intelligence

CVE-2019-14853: PYSEC-2019-177 - An error-handling flaw was found in python-ecdsa before version 0.13.3. During signature decoding, malformed DER signatures could raise unex

CVE-2019-14853 · Severity: low · CVSS 3.1 · Published 2019-11-26

Technologies: ecdsa (PyPI). Vendors: PyPI.

Executive brief

python-ecdsa is a widely-used cryptographic library for handling ECDSA (Elliptic Curve Digital Signature Algorithm) signatures in Python applications. A vulnerability in signature decoding can cause unexpected exceptions that lead to denial of service, disrupting applications that rely on this library for cryptographic operations. This affects all versions prior to 0.13.3.

Technical details

The vulnerability exists in the signature decoding logic of python-ecdsa (versions prior to 0.13.3), where malformed or invalid signature input triggers unexpected and undocumented exceptions rather than being handled gracefully. An attacker can craft malformed ECDSA signatures that, when processed by an application using the library, cause the application to raise exceptions and potentially crash. The attack is triggered when an application attempts to verify or decode a signature; no authentication is required. The fix is available in version 0.13.3 and later.

Affected products

  • python-ecdsa ecdsa before 0.13.3

Timeline

  • 2019-10-04: disclosed
  • 2019-10-07: patched: Version 0.13.3 released
  • 2019-12-02: advisory
  • 2020-06-16: other: Advisory withdrawn as duplicate of GHSA-pwfw-mgfj-7g3g

References

Related threats