PT-2024-40944 · Sharks · Sharks

Published

2024-11-16

·

Updated

2024-11-16

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions sharks (affected versions not specified)
Description The issue concerns a bias in generating random polynomials for Shamir Secret Sharing. Instead of coefficients being in the range [0, 255], they were in the range [1, 255]. This allows an attacker to exclude possible values for the shared secret, making it easier to brute force. The attack requires the same secret to be shared multiple times, with an estimated 500-1500 shares needed to reconstruct the secret under ideal circumstances. Secrets shared only once are not impacted, but repeatedly shared secrets may be vulnerable.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

RUSTSEC-2024-0398

Affected Products

Sharks