VDB
Sign up
—

RUSTSEC-2024-0392

Ambiguous challenge derivation

Details

Challenge derivation in non-interactive ZK proofs was ambiguous and that could lead to security vulnerability (however, it's unknown if it could be exploited).

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/cggmp21-keygen
Introduced in: 0.0.0-0Fixed in: 0.3.0

Upgrade cggmp21-keygen to 0.3.0 or newer (ecosystem crates.io).

References