DirectorySecurity Advisories
Sign In
Security Advisories

CGA-hpm6-2qvq-4337

Published

Last updated

https://images.chainguard.dev/security/CGA-hpm6-2qvq-4337
Package

zed

Latest Update
Fixed
Fixed Version

0.166.1-r0

Aliases
  • GHSA-4grx-2x9w-596c

Severity

5.9

Medium

CVSS V3

Summary

Marvin Attack: potential key recovery through timing sidechannels

Description

The Marvin Attack is a timing sidechannel vulnerability which allows performing RSA decryption and signing operations as an attacker with the ability to observe only the time of the decryption operation performed withthe private key.

A recent survey of RSA implementations found that the Rust rsa crate is one of many implementations vulnerable to this attack.

No fixed version is available at this time.

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images