Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Jim Miller

Researcher fromTrail of Bits
#40404of 53,635
6.8Total CVSS
Vulnerabilities · 1
PT-2022-19701
6.8
2022-04-21
Unknown · Bulletproofs · CVE-2022-29566
**Name of the Vulnerable Software and Affected Versions** Bulletproofs (affected versions not specified) **Description** The issue arises from the mishandling of Fiat-Shamir generation in the Bulletproofs 2017/1066 paper. Specifically, the hash computation fails to include all public values from the Zero Knowledge proof statement and all public values computed in the proof, also known as the Frozen Heart issue. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.