PT-2023-33034 · Unknown · Ed25519-Dalek+1

Published

2023-11-07

·

Updated

2023-11-07

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions ed25519-dalek versions prior to 2.0 rusty-paseto versions prior to 0.6.0
Description The issue arises from a "Double Public Key Signing Function Oracle Attack" affecting the ed25519-dalek crate, which is a dependency of the rusty-paseto crate. This vulnerability exposes an unsafe API for serializing and deserializing 64-byte keypairs that include both private and public keys, creating potential for certain attacks. Users of ed25519-dalek utilizing these serialization and deserialization functions directly could potentially be impacted.
Recommendations For ed25519-dalek versions prior to 2.0, update to version 2.0 or later. For rusty-paseto versions prior to 0.6.0, upgrade to version 0.6.0 or later. As a general best practice, ensure that key serialization and deserialization practices are secure and avoid any practices that could lead to key exposure.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

GHSA-J57R-4QW6-58R3

Affected Products

Ed25519-Dalek
Rusty-Paseto