Critical severityNVD Advisory· Published Aug 8, 2021· Updated Aug 4, 2024
CVE-2021-38195
CVE-2021-38195
Description
An issue was discovered in the libsecp256k1 crate before 0.5.0 for Rust. It can verify an invalid signature because it allows the R or S parameter to be larger than the curve order, aka an overflow.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
libsecp256k1crates.io | < 0.5.0 | 0.5.0 |
Affected products
2- libsecp256k1/libsecp256k1description
Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-g4vj-x7v9-h82mghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-38195ghsaADVISORY
- github.com/paritytech/libsecp256k1/pull/67ghsaWEB
- raw.githubusercontent.com/rustsec/advisory-db/main/crates/libsecp256k1/RUSTSEC-2021-0076.mdmitrex_refsource_MISC
- rustsec.org/advisories/RUSTSEC-2021-0076.htmlghsax_refsource_MISCWEB
News mentions
0No linked articles in our index yet.