Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Andersson Calle Viera

Researcher fromThales (France), Laboratoire de Recherche en Informatique de Paris 6
#37654of 53,633
7.5Total CVSS
Vulnerabilities · 1
PT-2023-19366
7.5
2023-01-20
Pqclean · Pqclean · CVE-2023-24025
**Name of the Vulnerable Software and Affected Versions** PQClean version d03da30 **Description** The issue allows universal forgeries of digital signatures via a template side-channel attack because of intermediate data leakage of one vector. This is related to CRYSTALS-DILITHIUM in Post-Quantum Cryptography Selected Algorithms 2022. **Recommendations** For PQClean version d03da30, consider applying a patch or fix to prevent intermediate data leakage and mitigate the risk of universal forgeries of digital signatures. As a temporary workaround, consider restricting access to the digital signature functionality until a patch is available.