-
Notifications
You must be signed in to change notification settings - Fork 10
Open
Labels
bugSomething isn't workingSomething isn't workinggoslinggosling crate issuegosling crate issueproject 5Part of Project 5 (Q2 2023)Part of Project 5 (Q2 2023)
Description
Description:
The rsa crate is subject to a timing side channel attack.
Technical description:
The rsa crate is susceptible to a Marvin attack (https://www.redhat.com/en/blog/marvin-attack) tracked here https://rustsec.org/advisories/RUSTSEC-2023-0071.html, which takes advantage of non-constant time operations in RSAES-PKCS1-v1_5. The Gosling crates do not directly use the vulnerable methods.
Impact:
The jitter of the Tor network makes such a vulnerability even harder to exploit, but if it were to be exploited then confidentiality could be compromised.
Recommendation:
- There is currently no patch available. Keep abreast of new developments and update the dependency once a fix is available.
Metadata
Metadata
Assignees
Labels
bugSomething isn't workingSomething isn't workinggoslinggosling crate issuegosling crate issueproject 5Part of Project 5 (Q2 2023)Part of Project 5 (Q2 2023)