python-ecdsa: Unexpected and undocumented exceptions during signature decoding
Published Nov 26, 2019
8.7
HIGHCVSS 4.0
EPSS 2.41%
Description
An error-handling flaw was found in python-ecdsa before version 0.13.3. During signature decoding, malformed DER signatures could raise unexpected exceptions (or no exceptions at all), which could lead to a denial of service.
Affected products
- Vendor n/a Product Python-Ecdsa Defaultn/a
- Version 0.13.3StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Python-Ecdsa | n/a |
|
- < 0.13.3
No data.
Red Hat Satellite 6.10 for RHEL 7
python-ecdsa-0:0.13.3-2.el7pc
Fixed · RHSA-2021:4702
Red Hat Satellite 6.10 for RHEL 7
python-ecdsa-0:0.13.3-2.el7pc
Fixed · RHSA-2021:4702
CloudForms Management Engine 5
python-ecdsa
Not affected
Red Hat Ceph Storage 2
python-ecdsa
Fix deferred
Red Hat OpenStack Platform 10 (Newton)
python-ecdsa
Will not fix
Red Hat OpenStack Platform 13 (Queens)
python-ecdsa
Will not fix
Red Hat OpenStack Platform 14 (Rocky)
python-ecdsa
Will not fix
Red Hat OpenStack Platform 15 (Stein)
python-ecdsa
Will not fix
Red Hat Storage 3
python-ecdsa
Affected
Red Hat Virtualization 4
python-ecdsa
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Satellite 6.10 for RHEL 7 | python-ecdsa-0:0.13.3-2.el7pc | Fixed | RHSA-2021:4702 |
| Red Hat Satellite 6.10 for RHEL 7 | python-ecdsa-0:0.13.3-2.el7pc | Fixed | RHSA-2021:4702 |
| CloudForms Management Engine 5 | python-ecdsa | Not affected | n/a |
| Red Hat Ceph Storage 2 | python-ecdsa | Fix deferred | n/a |
| Red Hat OpenStack Platform 10 (Newton) | python-ecdsa | Will not fix | n/a |
| Red Hat OpenStack Platform 13 (Queens) | python-ecdsa | Will not fix | n/a |
| Red Hat OpenStack Platform 14 (Rocky) | python-ecdsa | Will not fix | n/a |
| Red Hat OpenStack Platform 15 (Stein) | python-ecdsa | Will not fix | n/a |
| Red Hat Storage 3 | python-ecdsa | Affected | n/a |
| Red Hat Virtualization 4 | python-ecdsa | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Although Red Hat OpenStack Platform ships the flawed code, RHOSP does not actually use python-ecdsa's functionality. As such, Red Hat OpenStack Platform will not be providing a fix for python-ecdsa at this time. Current releases of Red Hat Virtualization Manager no longer includes python-ecdsa as a dependency. While it remains available in repositories as a legacy dependency, it is not installed by default and its use is not recommended.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
AV:N/AC:L/Au:N/C:N/I:N/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (15 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 2.41% (0.02407) | 83.50th | v5 (v2026.06.15) |
| Jun 15, 2026 | 2.50% (0.02505) | 82.61th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.05% (0.00052) | 13.45th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.29% (0.00289) | 69.76th | v3 (v2023.03.01) |
| Sep 30, 2023 | 0.19% (0.00195) | 56.95th | v3 (v2023.03.01) |
| Sep 15, 2023 | 0.20% (0.00201) | 57.59th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.17% (0.00168) | 52.01th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.02% (0.01018) | 40.69th | v2 (v2022.01.01) |
| Sep 10, 2022 | 1.02% (0.01018) | 38.88th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.02% (0.01018) | 36.86th | v2 (v2022.01.01) |
| Feb 4, 2022 | 7.18% (0.07176) | 80.33th | v2 (v2022.01.01) |
| Feb 3, 2022 | 5.55% (0.05553) | 80.10th | v1 |
| Jan 6, 2022 | 5.55% (0.05553) | 79.90th | v1 |
| Sep 1, 2021 | 1.29% (0.01294) | 69.02th | v1 |
| Apr 14, 2021 | 1.29% (0.01294) | 0.00th | v1 |
References (11)
- https://access.redhat.com/security/cve/CVE-2019-14853 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1758704 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14853 x_refsource_CONFIRMIssue TrackingThird Party Advisory
- https://github.com/advisories/GHSA-pwfw-mgfj-7g3g Advisory
- https://github.com/pypa/advisory-database/tree/main/vulns/ecdsa/PYSEC-2019-177.yaml
- https://github.com/warner/python-ecdsa/releases/tag/python-ecdsa-0.13.3 x_refsource_MISCRelease Notes
- https://github.com/warner/python-ecdsa/security/advisories/GHSA-pwfw-mgfj-7g3g
- https://nvd.nist.gov/vuln/detail/CVE-2019-14853
- https://seclists.org/bugtraq/2019/Dec/33 mailing-listx_refsource_BUGTRAQ
- https://www.cve.org/CVERecord?id=CVE-2019-14853
- https://www.debian.org/security/2019/dsa-4588 vendor-advisoryx_refsource_DEBIAN
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2019-14853 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1758704 | Issue Tracking | |
| https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14853 | x_refsource_CONFIRMIssue TrackingThird Party Advisory | |
| https://github.com/advisories/GHSA-pwfw-mgfj-7g3g | Advisory | |
| https://github.com/pypa/advisory-database/tree/main/vulns/ecdsa/PYSEC-2019-177.yaml | ||
| https://github.com/warner/python-ecdsa/releases/tag/python-ecdsa-0.13.3 | x_refsource_MISCRelease Notes | |
| https://github.com/warner/python-ecdsa/security/advisories/GHSA-pwfw-mgfj-7g3g | ||
| https://nvd.nist.gov/vuln/detail/CVE-2019-14853 | ||
| https://seclists.org/bugtraq/2019/Dec/33 | mailing-listx_refsource_BUGTRAQ | |
| https://www.cve.org/CVERecord?id=CVE-2019-14853 | ||
| https://www.debian.org/security/2019/dsa-4588 | vendor-advisoryx_refsource_DEBIAN |
Change history (0)
No recorded changes yet.