MEDIUM5.9
GHSA-4grx-2x9w-596c
Marvin Attack: potential key recovery through timing sidechannels
Details
The [Marvin Attack] is a timing sidechannel vulnerability which allows performing RSA decryption and signing operations as an attacker with the ability to observe only the time of the decryption operation performed withthe private key.
A recent survey of RSA implementations found that the Rust `rsa` crate is one of many implementations vulnerable to this attack.
No fixed version is available at this time.
[Marvin Attack]: https://people.redhat.com/~hkario/marvin/
Are you affected?
Enter the version of the package you're using.
Affected packages
crates.io/rsa
Introduced in:
0No fixed version published yet for rsa. Pin to a known-safe version or switch to an alternative.