PT-2024-40944 · Sharks · Sharks
Published
2024-11-16
·
Updated
2024-11-16
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions
sharks (affected versions not specified)
Description
The issue concerns a bias in generating random polynomials for Shamir Secret Sharing. Instead of coefficients being in the range
[0, 255], they were in the range [1, 255]. This allows an attacker to exclude possible values for the shared secret, making it easier to brute force. The attack requires the same secret to be shared multiple times, with an estimated 500-1500 shares needed to reconstruct the secret under ideal circumstances. Secrets shared only once are not impacted, but repeatedly shared secrets may be vulnerable.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sharks