GHSA-92vm-mxjf-jqf3
CRITICALCVE-2021-43572The verify function in the Stark Bank Python ECDSA library (starkbank-ecdsa) 2.0.0 fails to check that the signature is non-zero, which allows attackers to forge signatures on arbitrary messages.
- Affected
- < 2.0.1
- Fixed in
- 2.0.1
- Weakness
- CWE-347
- Published
- 2021-11-10
- Source
- github