Skip to content
Snippets Groups Projects
  1. May 03, 2022
    • Matthias Schiffer's avatar
      ecdsautils: verify: fix signature verification (CVE-2022-24884) · 5e6bac4e
      Matthias Schiffer authored
      A vulnerability was found in ecdsautils which allows forgery of ECDSA
      signatures. An adversary exploiting this vulnerability can create an update
      manifest accepted by the autoupdater, which can be used to distribute
      malicious firmware updates by spoofing a Gluon node's connection to the
      update server.
      5e6bac4e
Loading