High severity8.8NVD Advisory· Published Jun 7, 2020· Updated Jun 17, 2026
CVE-2020-13895
CVE-2020-13895
Description
Crypt::Perl::ECDSA in the Crypt::Perl (aka p5-Crypt-Perl) module before 0.32 for Perl fails to verify correct ECDSA signatures when r and s are small and when s = 1. This happens when using the curve secp256r1 (prime256v1). This could conceivably have a security-relevant impact if an attacker wishes to use public r and s values when guessing whether signature verification will fail.
Affected products
2- Crypt::Perl/Crypt::Perldescription
- Range: <0.32
Patches
Vulnerability mechanics
References
2- github.com/FGasper/p5-Crypt-Perl/commit/f960ce75502acf7404187231a706672f8369acb2nvdPatchThird Party Advisory
- github.com/FGasper/p5-Crypt-Perl/issues/14nvdThird Party Advisory
News mentions
0No linked articles in our index yet.