Files
advisory-db/crates/streebog/RUSTSEC-2019-0030.md
2023-06-13 15:10:24 +02:00

568 B

[advisory]
id = "RUSTSEC-2019-0030"
package = "streebog"
aliases = ["CVE-2019-25006", "CVE-2019-25007", "CVE-2020-25575", "GHSA-39wr-f4ff-xm6p", "GHSA-gf93-h79q-6jjv", "GHSA-jq66-xh47-j9f3"]
categories = ["crypto-failure"]
date = "2019-10-06"
url = "https://github.com/RustCrypto/hashes/pull/91"

[versions]
patched = [">= 0.8.0"]

Incorrect implementation of the Streebog hash functions

Internal update-sigma function was implemented incorrectly and depending on debug-assertions it could've caused an incorrect result or panic for certain inputs.