Junglewise Threat Intelligence

CVE-2021-43572: PYSEC-2021-426 - The verify function in the Stark Bank Python ECDSA library (ecdsa-python) 2.0.0 fails to check that the signature is non-zero, which allows

CVE-2021-43572 · Severity: low · CVSS 3.1 · Published 2021-11-09

Vendors: PyPI.

Executive brief

The verify function in the Stark Bank Python ECDSA library (ecdsa-python) 2.0.0 fails to check that the signature is non-zero, which allows attackers to forge signatures on arbitrary messages.

Affected products

  • PyPI starkbank-ecdsa

Related threats