CRYSTALS-DILITHIUM (in Post-Quantum Cryptography Selected Algorithms 2022) in PQClean d03da30 may allow universal forgeries of digital signatures via a template side-channel attack because of intermediate data leakage of one vector.
References
Link | Resource |
---|---|
https://csrc.nist.gov/Projects/post-quantum-cryptography/selected-algorithms-2022 | Third Party Advisory US Government Resource |
https://eprint.iacr.org/2023/050 | Third Party Advisory |
https://github.com/PQClean/PQClean/tree/d03da3053491e767ef842deaef43fc5bdb6bc911 | Third Party Advisory |
https://csrc.nist.gov/Projects/post-quantum-cryptography/selected-algorithms-2022 | Third Party Advisory US Government Resource |
https://eprint.iacr.org/2023/050 | Third Party Advisory |
https://github.com/PQClean/PQClean/tree/d03da3053491e767ef842deaef43fc5bdb6bc911 | Third Party Advisory |
Configurations
History
21 Nov 2024, 07:47
Type | Values Removed | Values Added |
---|---|---|
References | () https://csrc.nist.gov/Projects/post-quantum-cryptography/selected-algorithms-2022 - Third Party Advisory, US Government Resource | |
References | () https://eprint.iacr.org/2023/050 - Third Party Advisory | |
References | () https://github.com/PQClean/PQClean/tree/d03da3053491e767ef842deaef43fc5bdb6bc911 - Third Party Advisory |
Information
Published : 2023-01-20 21:15
Updated : 2024-11-21 07:47
NVD link : CVE-2023-24025
Mitre link : CVE-2023-24025
CVE.ORG link : CVE-2023-24025
JSON object : View
Products Affected
pqclean_project
- pqclean
CWE
CWE-347
Improper Verification of Cryptographic Signature