High severityNVD Advisory· Published Oct 26, 2023· Updated Feb 13, 2025
browserify-sign vulnerable via an upper bound check issue in `dsaVerify` that leads to a signature forgery attack
CVE-2023-46234
Description
browserify-sign is a package to duplicate the functionality of node's crypto public key functions, much of this is based on Fedor Indutny's work on indutny/tls.js. An upper bound check issue in dsaVerify function allows an attacker to construct signatures that can be successfully verified by any public key, thus leading to a signature forgery attack. All places in this project that involve DSA verification of user-input signatures will be affected by this vulnerability. This issue has been patched in version 4.2.2.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
browserify-signnpm | >= 2.6.0, < 4.2.2 | 4.2.2 |
Affected products
3- ghsa-coords2 versions
>= 2.6.0, < 4.2.2+ 1 more
- (no CPE)range: >= 2.6.0, < 4.2.2
- (no CPE)range: < 0.7.0.4.git142.862ef23-1.1
- Range: >= 2.6.0, <= 4.2.1
Patches
Vulnerability mechanics
References
10- github.com/advisories/GHSA-x9w5-v3q2-3rhwghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-46234ghsaADVISORY
- github.com/browserify/browserify-sign/commit/85994cd6348b50f2fd1b73c54e20881416f44a30ghsax_refsource_MISCWEB
- github.com/browserify/browserify-sign/security/advisories/GHSA-x9w5-v3q2-3rhwghsax_refsource_CONFIRMWEB
- lists.debian.org/debian-lts-announce/2023/10/msg00040.htmlghsaWEB
- lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3HUE6ZR5SL73KHL7XUPAOEL6SB7HUDT2ghsaWEB
- lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6PVVPNSAGSDS63HQ74PJ7MZ3MU5IYNVZghsaWEB
- www.debian.org/security/2023/dsa-5539ghsaWEB
- lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3HUE6ZR5SL73KHL7XUPAOEL6SB7HUDT2/mitre
- lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6PVVPNSAGSDS63HQ74PJ7MZ3MU5IYNVZ/mitre
News mentions
0No linked articles in our index yet.