The verify function in lib/elliptic/eddsa/index.js in the Elliptic package before 6.5.6 for Node.js omits "sig.S().gte(sig.eddsa.curve.n) || sig.S().isNeg()" validation.
{ "binaries": [ { "binary_name": "node-elliptic", "binary_version": "6.4.0+dfsg-1" } ] }
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-48949.json"
{ "binaries": [ { "binary_name": "node-elliptic", "binary_version": "6.5.1~dfsg-2" } ] }
{ "binaries": [ { "binary_name": "node-elliptic", "binary_version": "6.5.4~dfsg-1" } ] }
{ "binaries": [ { "binary_name": "node-elliptic", "binary_version": "6.5.4~dfsg-2" } ] }