rustsec / advisory-db

Security advisory database for Rust crates published through crates.io
https://rustsec.org
Other
887 stars 339 forks source link

Add advisory for curve25519-dalek timing variability #1981

Closed tarcieri closed 3 weeks ago

tarcieri commented 3 weeks ago

This impacts scalar types which represent private keys and other secrets. This vulnerability could potentially result in leakage of these values by observing the variability.