Critical severity9.1NVD Advisory· Published Jan 2, 2020· Updated Jun 17, 2026
CVE-2019-14859
CVE-2019-14859
Description
A flaw was found in all python-ecdsa versions before 0.13.3, where it did not correctly verify whether signatures used DER encoding. Without this verification, a malformed signature could be accepted, making the signature malleable. Without proper verification, an attacker could use a malleable signature to create false transactions.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
ecdsaPyPI | < 0.13.3 | 0.13.3 |
Affected products
27- Red Hat/python-ecdsav5Range: all python-ecdsa versions before 0.13.3
- ghsa-coords18 versionspkg:pypi/ecdsapkg:rpm/suse/python-ecdsa&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP2pkg:rpm/suse/python-ecdsa&distro=SUSE%20OpenStack%20Cloud%20Crowbar%208pkg:rpm/suse/python-ecdsa&distro=SUSE%20OpenStack%20Cloud%209pkg:rpm/suse/python-ecdsa&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP1pkg:rpm/suse/python-ecdsa&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015pkg:rpm/suse/python-ecdsa&distro=SUSE%20OpenStack%20Cloud%207pkg:rpm/suse/python-ecdsa&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Public%20Cloud%2015pkg:rpm/suse/python-ecdsa&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP2pkg:rpm/suse/python-ecdsa&distro=HPE%20Helion%20OpenStack%208pkg:rpm/suse/python-ecdsa&distro=SUSE%20OpenStack%20Cloud%208pkg:rpm/suse/python-ecdsa&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Public%20Cloud%2012pkg:rpm/suse/python-ecdsa&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP1pkg:rpm/opensuse/python-ecdsa&distro=openSUSE%20Leap%2015.0pkg:rpm/opensuse/python-ecdsa&distro=openSUSE%20Leap%2015.1pkg:rpm/suse/python-ecdsa&distro=SUSE%20OpenStack%20Cloud%20Crowbar%209pkg:rpm/suse/python-ecdsa&distro=SUSE%20Manager%20Server%203.2pkg:rpm/opensuse/python-ecdsa&distro=openSUSE%20Tumbleweed
< 0.13.3+ 17 more
- (no CPE)range: < 0.13.3
- (no CPE)range: < 0.13.3-3.3.1
- (no CPE)range: < 0.13.3-5.10.1
- (no CPE)range: < 0.13.3-5.10.1
- (no CPE)range: < 0.13.3-3.3.1
- (no CPE)range: < 0.13.3-3.3.1
- (no CPE)range: < 0.13.3-5.10.1
- (no CPE)range: < 0.13.3-3.3.1
- (no CPE)range: < 0.13.3-3.3.1
- (no CPE)range: < 0.13.3-5.10.1
- (no CPE)range: < 0.13.3-5.10.1
- (no CPE)range: < 0.13.3-5.10.1
- (no CPE)range: < 0.13.3-3.3.1
- (no CPE)range: < 0.13.3-lp150.2.3.1
- (no CPE)range: < 0.13.3-lp151.3.3.1
- (no CPE)range: < 0.13.3-5.10.1
- (no CPE)range: < 0.13.3-5.10.1
- (no CPE)range: < 0.16.1-1.5
- cpe:2.3:a:python-ecdsa_project:python-ecdsa:*:*:*:*:*:*:*:*Range: <0.13.3
cpe:2.3:a:redhat:ceph_storage:2.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:redhat:ceph_storage:2.0:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:ceph_storage:3.0:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:virtualization:4.0:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
12- bugzilla.redhat.com/show_bug.cginvdExploitIssue TrackingPatchThird Party AdvisoryWEB
- github.com/warner/python-ecdsa/issues/114nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-8qxj-f9rh-9fg2ghsaADVISORY
- github.com/warner/python-ecdsa/releases/tag/python-ecdsa-0.13.3nvdRelease NotesThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2019-14859ghsaADVISORY
- pypi.org/project/ecdsa/0.13.3/nvdRelease NotesThird Party Advisory
- github.com/pypa/advisory-database/tree/main/vulns/ecdsa/PYSEC-2020-163.yamlghsaWEB
- github.com/tlsfuzzer/python-ecdsa/commit/3427fa29f319b27898a28601955807abb44c0830ghsaWEB
- github.com/tlsfuzzer/python-ecdsa/commit/9080d1d5ac533da0de00466aaffb49bee808bb4eghsaWEB
- github.com/tlsfuzzer/python-ecdsa/commit/b0ea52bb3aa9a16c9a4a91fdc0041edbfed10b31ghsaWEB
- github.com/warner/python-ecdsa/pull/115ghsaWEB
- pypi.org/project/ecdsa/0.13.3ghsaWEB
News mentions
0No linked articles in our index yet.