U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2024-21502

Change History

New CVE Received by NIST 2/24/2024 12:15:44 AM

Action Type Old Value New Value
Added CVSS V3.1

								
							
							
						
Snyk AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Added CWE

								
							
							
						
Snyk CWE-457
Added Description

								
							
							
						
Versions of the package fastecdsa before 2.3.2 are vulnerable to Use of Uninitialized Variable on the stack, via the curvemath_mul function in src/curveMath.c, due to being used and interpreted as user-defined type. Depending on the variable's actual value it could be arbitrary free(), arbitrary realloc(), null pointer dereference and other. Since the stack can be controlled by the attacker, the vulnerability could be used to corrupt allocator structure, leading to possible heap exploitation. The attacker could cause denial of service by exploiting this vulnerability.
Added Reference

								
							
							
						
Snyk https://gist.github.com/keltecc/49da037072276f21b005a8337c15db26 [No types assigned]
Added Reference

								
							
							
						
Snyk https://github.com/AntonKueltz/fastecdsa/blob/v2.3.1/src/curveMath.c%23L210 [No types assigned]
Added Reference

								
							
							
						
Snyk https://github.com/AntonKueltz/fastecdsa/commit/57fc5689c95d649dab7ef60cc99ac64589f01e36 [No types assigned]
Added Reference

								
							
							
						
Snyk https://security.snyk.io/vuln/SNYK-PYTHON-FASTECDSA-6262045 [No types assigned]