PT-2023-33034 · Unknown · Ed25519-Dalek+1

Published

2023-11-07

·

Updated

2023-11-07

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions ed25519-dalek versions prior to 2.0 rusty-paseto versions prior to 0.6.0
Description The issue arises from a "Double Public Key Signing Function Oracle Attack" affecting the ed25519-dalek crate, which is a dependency of the rusty-paseto crate. This vulnerability exposes an unsafe API for serializing and deserializing 64-byte keypairs that include both private and public keys, creating potential for certain attacks. Users of ed25519-dalek utilizing these serialization and deserialization functions directly could potentially be impacted.
Recommendations For ed25519-dalek versions prior to 2.0, update to version 2.0 or later. For rusty-paseto versions prior to 0.6.0, upgrade to version 0.6.0 or later. As a general best practice, ensure that key serialization and deserialization practices are secure and avoid any practices that could lead to key exposure.

Related Identifiers

GHSA-J57R-4QW6-58R3

Affected Products

Ed25519-Dalek
Rusty-Paseto