{"id":"GHSA-h864-m8vm-3xvj","aliases":["RUSTSEC-2022-0047"],"url":"https://o3.security/vulnerability/GHSA-h864-m8vm-3xvj","summary":"oqs's Post-Quantum Signature scheme Rainbow level I parametersets broken","details":"Ward Beullens found a practical key-recovery attack against Rainbow.\nThe level I parametersets are removed from liboqs starting from version `0.7.2`.\nFind the scientific details in [Breaking Rainbow Takes a Weekend on a Laptop](https://eprint.iacr.org/2022/214).\n\nThis means all the `oqs::sig::Algorithm::RainbowI*` variants are insecure.\n","published":"2022-08-18T19:06:39Z","modified":"2023-11-08T04:19:57.153953Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"crates.io","name":"oqs","fixedVersion":"0.7.2"}],"fix":null,"references":[{"type":"PACKAGE","url":"https://github.com/open-quantum-safe/liboqs-rust"},{"type":"WEB","url":"https://groups.google.com/a/list.nist.gov/g/pqc-forum/c/KFgw5_qCXiI?pli=1"},{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2022-0047.html"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2023-11-08T04:19:57.153953Z"}}