starkbank-ecdsa
Pure C# implementation of the Elliptic Curve Digital Signature Algorithm (ECDSA) by Stark Bank
Activity
- Latest release
- 4y ago
- Total releases
- 9
- Cadence
- ~3 months
- Last 12 months
- 0
Details
- First release
- Jan 07, 2020
| Version | Released | |
|---|---|---|
1.3.3
patch
| ||
1.3.2
patch
| ||
1.3.1
patch
2 CVEs
CVE-2021-43569
GHSA-j3jw-j2j8-2wv9
Nov 10, 2021
Improper Verification of Cryptographic Signature in starkbank-ecdsa
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The verify function in the Stark Bank .NET ECDSA library (ecdsa-dotnet) 1.3.1 fails to check that the signature is non-zero, which allows attackers to forge signatures on arbitrary messages. Affected versions
0.0.1
1.0.0
1.1.0
1.2.0
1.2.1
1.3.0
1.3.1
Fixed in
1.3.2
References Updated Feb 17, 2024 · Source: OSV.dev
GHSA-9wx7-jrvc-28mm
Nov 08, 2021
Signature verification vulnerability in Stark Bank ecdsa libraries
High
An attacker can forge signatures on arbitrary messages that will verify for any public key. This may allow attackers to authenticate as any user within the Stark Bank platform, and bypass signature verification needed to perform operations on the platform, such as send payments and transfer funds. Additionally, the ability for attackers to forge signatures may impact other users and projects using these libraries in different and unforeseen ways. Affected versions
1.3.1
Fixed in
1.3.2
References
Updated Dec 06, 2024 · Source: OSV.dev | ||
1.3.0
minor
1 CVE
CVE-2021-43569
GHSA-j3jw-j2j8-2wv9
Nov 10, 2021
Improper Verification of Cryptographic Signature in starkbank-ecdsa
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The verify function in the Stark Bank .NET ECDSA library (ecdsa-dotnet) 1.3.1 fails to check that the signature is non-zero, which allows attackers to forge signatures on arbitrary messages. Affected versions
0.0.1
1.0.0
1.1.0
1.2.0
1.2.1
1.3.0
1.3.1
Fixed in
1.3.2
References Updated Feb 17, 2024 · Source: OSV.dev | ||
1.2.1
patch
1 CVE
CVE-2021-43569
GHSA-j3jw-j2j8-2wv9
Nov 10, 2021
Improper Verification of Cryptographic Signature in starkbank-ecdsa
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The verify function in the Stark Bank .NET ECDSA library (ecdsa-dotnet) 1.3.1 fails to check that the signature is non-zero, which allows attackers to forge signatures on arbitrary messages. Affected versions
0.0.1
1.0.0
1.1.0
1.2.0
1.2.1
1.3.0
1.3.1
Fixed in
1.3.2
References Updated Feb 17, 2024 · Source: OSV.dev | ||
1.2.0
minor
1 CVE
CVE-2021-43569
GHSA-j3jw-j2j8-2wv9
Nov 10, 2021
Improper Verification of Cryptographic Signature in starkbank-ecdsa
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The verify function in the Stark Bank .NET ECDSA library (ecdsa-dotnet) 1.3.1 fails to check that the signature is non-zero, which allows attackers to forge signatures on arbitrary messages. Affected versions
0.0.1
1.0.0
1.1.0
1.2.0
1.2.1
1.3.0
1.3.1
Fixed in
1.3.2
References Updated Feb 17, 2024 · Source: OSV.dev | ||
1.1.0
minor
1 CVE
CVE-2021-43569
GHSA-j3jw-j2j8-2wv9
Nov 10, 2021
Improper Verification of Cryptographic Signature in starkbank-ecdsa
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The verify function in the Stark Bank .NET ECDSA library (ecdsa-dotnet) 1.3.1 fails to check that the signature is non-zero, which allows attackers to forge signatures on arbitrary messages. Affected versions
0.0.1
1.0.0
1.1.0
1.2.0
1.2.1
1.3.0
1.3.1
Fixed in
1.3.2
References Updated Feb 17, 2024 · Source: OSV.dev | ||
1.0.0
major
1 CVE
CVE-2021-43569
GHSA-j3jw-j2j8-2wv9
Nov 10, 2021
Improper Verification of Cryptographic Signature in starkbank-ecdsa
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The verify function in the Stark Bank .NET ECDSA library (ecdsa-dotnet) 1.3.1 fails to check that the signature is non-zero, which allows attackers to forge signatures on arbitrary messages. Affected versions
0.0.1
1.0.0
1.1.0
1.2.0
1.2.1
1.3.0
1.3.1
Fixed in
1.3.2
References Updated Feb 17, 2024 · Source: OSV.dev | ||
0.0.1
initial
1 CVE
CVE-2021-43569
GHSA-j3jw-j2j8-2wv9
Nov 10, 2021
Improper Verification of Cryptographic Signature in starkbank-ecdsa
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The verify function in the Stark Bank .NET ECDSA library (ecdsa-dotnet) 1.3.1 fails to check that the signature is non-zero, which allows attackers to forge signatures on arbitrary messages. Affected versions
0.0.1
1.0.0
1.1.0
1.2.0
1.2.1
1.3.0
1.3.1
Fixed in
1.3.2
References Updated Feb 17, 2024 · Source: OSV.dev |