Vulnerability Details CVE-2019-14859
A flaw was found in all python-ecdsa versions before 0.13.3, where it did not correctly verify whether signatures used DER encoding. Without this verification, a malformed signature could be accepted, making the signature malleable. Without proper verification, an attacker could use a malleable signature to create false transactions.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 27.9%
CVSS Severity
CVSS v3 Score 7.4
CVSS v2 Score 6.4
Products affected by CVE-2019-14859
-
cpe:2.3:a:python-ecdsa_project:python-ecdsa:0.10
-
cpe:2.3:a:python-ecdsa_project:python-ecdsa:0.11
-
cpe:2.3:a:python-ecdsa_project:python-ecdsa:0.12
-
cpe:2.3:a:python-ecdsa_project:python-ecdsa:0.13
-
cpe:2.3:a:python-ecdsa_project:python-ecdsa:0.13.1
-
cpe:2.3:a:python-ecdsa_project:python-ecdsa:0.13.2
-
cpe:2.3:a:python-ecdsa_project:python-ecdsa:0.5
-
cpe:2.3:a:python-ecdsa_project:python-ecdsa:0.6
-
cpe:2.3:a:python-ecdsa_project:python-ecdsa:0.7
-
cpe:2.3:a:python-ecdsa_project:python-ecdsa:0.8
-
cpe:2.3:a:python-ecdsa_project:python-ecdsa:0.9
-
cpe:2.3:a:redhat:ceph_storage:2.0
-
cpe:2.3:a:redhat:ceph_storage:3.0
-
cpe:2.3:a:redhat:openstack:10
-
cpe:2.3:a:redhat:openstack:13
-
cpe:2.3:a:redhat:openstack:14
-
cpe:2.3:a:redhat:openstack:15
-
cpe:2.3:a:redhat:virtualization:4.0