Executive brief
The verify function in the Stark Bank Python ECDSA library (ecdsa-python) 2.0.0 fails to check that the signature is non-zero, which allows attackers to forge signatures on arbitrary messages.
Affected products
- PyPI starkbank-ecdsa
Junglewise Threat Intelligence
CVE-2021-43572 · Severity: low · CVSS 3.1 · Published 2021-11-09
Vendors: PyPI.
The verify function in the Stark Bank Python ECDSA library (ecdsa-python) 2.0.0 fails to check that the signature is non-zero, which allows attackers to forge signatures on arbitrary messages.