VDB
Sign up
HIGH7.5

GHSA-hrjm-c879-pp86

libsecp256k1 contains side-channel timing attack

Details

Versions of libsecp256k1 prior to 0.3.1 did not execute `Scalar::check_overflow` in constant time. This allows an attacker to potentially leak information via a timing attack. The flaw was corrected by modifying `Scalar::check_overflow` to execute in constant time.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/libsecp256k1
Introduced in: 0Fixed in: 0.3.1

Upgrade libsecp256k1 to 0.3.1 or newer (ecosystem crates.io).

References