rpgp icon indicating copy to clipboard operation
rpgp copied to clipboard

Dealing with RUSTSEC-2023-0071

Open link2xt opened this issue 1 year ago • 0 comments

This decrypt public API is a straight call into rsa crate with PKCS1v15 padding: https://github.com/rpgp/rpgp/blob/63f55a72d04c5cb81ab0fc56eac82c87e015ac12/src/crypto/rsa.rs#L25-L33

This is claimed to be vulnerable to timing attack at https://github.com/RustCrypto/RSA/issues/19 There is a security advisory at https://rustsec.org/advisories/RUSTSEC-2023-0071 without a fix currently.

rPGP should update to fixed rsa dependency or work around this somehow, but as far as I see there is no workaround and we need an rsa crate fix.

link2xt avatar Nov 28 '23 15:11 link2xt