Security controls bypass or absence In rsa
Description
Marvin Attack: potential key recovery through timing sidechannels The Marvin Attack is a timing sidechannel vulnerability which allows performing RSA decryption and signing operations as an attacker with the ability to observe only the time of the decryption operation performed withthe private key.
A recent survey of RSA implementations found that the Rust rsa crate is one of many implementations vulnerable to this attack.
No fixed version is available at this time.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
cargo | 0.10.0-pre.0 |
Aliases
1. 2.
References
1. 2. 3. 4.