CVE Vulnerabilities

CVE-2019-16992

Improper Verification of Cryptographic Signature

Published: Sep 30, 2019 | Modified: Oct 08, 2019
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

The Keybase app 2.13.2 for iOS provides potentially insufficient notice that it is employing a users private key to sign a certain cryptocurrency attestation (that an address at keybase.io can be used for Stellar payments to the user), which might be incompatible with a users personal position on the semantics of an attestation.

Weakness

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Affected Software

Name Vendor Start Version End Version
Keybase Keybase 2.13.2 (including) 2.13.2 (including)

References