High severityNVD Advisory· Published Aug 22, 2019· Updated Aug 4, 2024
CVE-2019-9153
CVE-2019-9153
Description
Improper Verification of a Cryptographic Signature in OpenPGP.js <=4.1.2 allows an attacker to forge signed messages by replacing its signatures with a "standalone" or "timestamp" signature.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
openpgpnpm | < 4.2.0 | 4.2.0 |
Affected products
2- OpenPGP.js/OpenPGP.jsdescription
Patches
Vulnerability mechanics
References
11- github.com/advisories/GHSA-qwqc-28w3-fww6ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2019-9153ghsaADVISORY
- packetstormsecurity.com/files/154191/OpenPGP.js-4.2.0-Signature-Bypass-Invalid-Curve-Attack.htmlghsax_refsource_MISCWEB
- github.com/openpgpjs/openpgpjs/pull/797/commits/327d3e5392a6f59a4270569d200c7f7a2bfc4cbcghsax_refsource_CONFIRMWEB
- github.com/openpgpjs/openpgpjs/pull/816ghsax_refsource_CONFIRMWEB
- github.com/openpgpjs/openpgpjs/releases/tag/v4.2.0ghsax_refsource_CONFIRMWEB
- sec-consult.com/en/blog/advisories/multiple-vulnerabilities-in-openpgp-jsghsaWEB
- sec-consult.com/en/blog/advisories/multiple-vulnerabilities-in-openpgp-js/mitrex_refsource_MISC
- snyk.io/vuln/SNYK-JS-OPENPGP-460248ghsaWEB
- www.bsi.bund.de/SharedDocs/Downloads/EN/BSI/Publications/Studies/Mailvelope_Extensions/Mailvelope_Extensions_pdf.htmlghsax_refsource_MISCWEB
- www.npmjs.com/advisories/1160ghsaWEB
News mentions
0No linked articles in our index yet.