VDB
Sign up
MEDIUM5.9

GHSA-7cqg-8449-rmfv

Observable Discrepancy in libsecp256k1-rs

Details

A timing vulnerability in the Scalar::check_overflow function in Parity libsecp256k1-rs before 0.3.1 potentially allows an attacker to leak information via a side-channel attack.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/libsecp256k1-rs
Introduced in: 0Fixed in: 0.3.1

Upgrade libsecp256k1-rs to 0.3.1 or newer (ecosystem crates.io).

References