RustCrypto/RSA

Marvin Attack: potential key recovery through timing sidechannels

ananduremanan opened this issue · 1 comments

I got the error

The Marvin Attack is a timing sidechannel vulnerability which allows performing RSA decryption and signing operations as an attacker with the ability to observe only the time of the decryption operation performed withthe private key.

A recent survey of RSA implementations found that the Rust rsa crate is one of many implementations vulnerable to this attack.

No fixed version is available at this time.

as a Dependabot alert in my github repository . What Does this means?

See #19.

As noted, there is currently no fix available. It's being worked on in #394.