RUSTSEC-2022-0047
Dashboard / Vulnerabilities / RUSTSEC-2022-0047
Summary: Post-Quantum Signature scheme Rainbow level I parametersets broken
Details: Ward Beullens found a practical key-recovery attack against Rainbow. The level I parametersets are removed from liboqs starting from version `0.7.2`. Find the scientific details in [Breaking Rainbow Takes a Weekend on a Laptop](https://eprint.iacr.org/2022/214). This means all the `oqs::sig::Algorithm::RainbowI*` variants are insecure.
References: https://crates.io/crates/oqs, https://rustsec.org/advisories/RUSTSEC-2022-0047.html, https://groups.google.com/a/list.nist.gov/g/pqc-forum/c/KFgw5_qCXiI?pli=1
Affected packages
Package
Name: oqs
Purl: pkg:cargo/oqs
Affected ranges
Type: SEMVER
Events:
Introduced- 0.0.0-0
Fixed -0.7.2
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
