Description
The `ecdsa` PyPI package is a pure Python implementation of ECC (Elliptic Curve Cryptography) with support for ECDSA (Elliptic Curve Digital Signature Algorithm), EdDSA (Edwards-curve Digital Signature Algorithm) and ECDH (Elliptic Curve Diffie-Hellman). Versions 0.18.0 and prior are vulnerable to the Minerva attack. As of time of publication, no known patched version exists.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-0448 | The `ecdsa` PyPI package is a pure Python implementation of ECC (Elliptic Curve Cryptography) with support for ECDSA (Elliptic Curve Digital Signature Algorithm), EdDSA (Edwards-curve Digital Signature Algorithm) and ECDH (Elliptic Curve Diffie-Hellman). Versions 0.18.0 and prior are vulnerable to the Minerva attack. As of time of publication, no known patched version exists. |
Github GHSA |
GHSA-wj6h-64fc-37mp | Minerva timing attack on P-256 in python-ecdsa |
References
History
Sat, 31 May 2025 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 05 Dec 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat satellite
Redhat satellite Capsule |
|
| CPEs | cpe:/a:redhat:satellite:6.15::el8 cpe:/a:redhat:satellite_capsule:6.15::el8 |
|
| Vendors & Products |
Redhat satellite
Redhat satellite Capsule |
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-05-30T14:21:45.651Z
Reserved: 2024-01-15T15:19:19.444Z
Link: CVE-2024-23342
Updated: 2024-08-01T22:59:32.162Z
Status : Analyzed
Published: 2024-01-23T00:15:26.397
Modified: 2025-08-26T21:33:47.870
Link: CVE-2024-23342
OpenCVE Enrichment
No data.
EUVD
Github GHSA