USN-4196-1: python-ecdsa vulnerabilities
18 November 2019
Several security issues were fixed in python-ecdsa.
- python-ecdsa - ECDSA cryptographic signature library
It was discovered that python-ecdsa incorrectly handled certain signatures.
A remote attacker could possibly use this issue to cause python-ecdsa to
generate unexpected exceptions, resulting in a denial of service.
It was discovered that python-ecdsa incorrectly verified DER encoding in
signatures. A remote attacker could use this issue to perform certain
malleability attacks. (CVE-2019-14859)
The problem can be corrected by updating your system to the following package versions:
In general, a standard system update will make all the necessary changes.