Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update ed25519-dalek due to RUSTSEC-2022-0093 #172

Closed
matthiasbeyer opened this issue Aug 15, 2023 · 1 comment
Closed

Update ed25519-dalek due to RUSTSEC-2022-0093 #172

matthiasbeyer opened this issue Aug 15, 2023 · 1 comment

Comments

@matthiasbeyer
Copy link

Dependabot just issued RUSTSEC-2022-0093 for a project of mine. The issue is resolved in ed25519-dalek starting from 2.0.0 of the crate.
This crate is a transitive dependency of my crate, hence I'm filing this here.

Can you please update your usage of the ed25519-dalek crate?

Eugeny added a commit that referenced this issue Aug 15, 2023
@Eugeny
Copy link
Owner

Eugeny commented Aug 15, 2023

I've bumped the library in #173 - would appreciate if you can look through it.
Do I understand it correctly that the vulnerability is only exploitable if there's an API that allows signing with an incoherent public/secret keypair? In that case, russh isn't directly affected since the keypair is encapsulated in russh_keys::Keypair after loading from a file/buffer

@Eugeny Eugeny closed this as completed in 43edc32 Aug 17, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants