Описание
Failure to properly verify ed25519 signatures in libp2p-core
Affected versions of this crate did not properly verify ed25519 signatures. Any signature with a correct length was considered valid. This allows an attacker to impersonate any node identity.
Пакеты
Наименование
libp2p-core
rust
Затронутые версииВерсия исправления
< 0.8.1
0.8.1
Связанные уязвимости
CVSS3: 7.5
nvd
больше 6 лет назад
An issue was discovered in the libp2p-core crate before 0.8.1 for Rust. Attackers can spoof ed25519 signatures.