CVE-2019-16753
An issue was discovered in Decentralized Anonymous Payment System (DAPS) through 2019-08-26. The content to be signed is composed of a representation of strings, rather than being composed of their binary representations. This is a weak signature scheme design that would allow the reuse of signatures in some cases (or even the reuse of signatures, intended for one type of message, for another type). This also affects Private Instant Verified Transactions (PIVX) through 3.4.0.
Published:Dec 4, 2019
Last Modified:Nov 21, 2024
EPS:Dec 4, 2019
EPSS Score:0.00183
CVSS Score:7.5
Affected Products
Vendor
Product
Action
Vendor
Decentralized Anonymous Payment System Project
Product
Decentralized Anonymous Payment System
Decentralized Anonymous Payment System Project
Decentralized Anonymous Payment System
Vendor
Pivx
Product
Private Instant Verified Transactions
Pivx
Private Instant Verified Transactions
Exploits
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
