VDB
Sign up
—

RUSTSEC-2021-0075

Flaw in `FieldVar::mul_by_inverse` allows unsound R1CS constraint systems

Details

Versions `0.2.0` to `0.3.0` of ark-r1cs-std did not enforce any constraints in the `FieldVar::mul_by_inverse` method, allowing a malicious prover to produce an unsound proof that passes all verifier checks. This method was used primarily in scalar multiplication for [`short_weierstrass::ProjectiveVar`](https://docs.rs/ark-r1cs-std/0.3.0/ark_r1cs_std/groups/curves/short_weierstrass/struct.ProjectiveVar.html).

This bug was fixed in commit `47ddbaa`, and was released as part of version `0.3.1` on `crates.io`.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/ark-r1cs-std
Introduced in: 0.0.0-0Fixed in: 0.3.1

Upgrade ark-r1cs-std to 0.3.1 or newer (ecosystem crates.io).

References