summaryrefslogtreecommitdiff
path: root/changes/curve25519-donna32-bug
diff options
context:
space:
mode:
authorNick Mathewson <nickm@torproject.org>2014-07-15 15:42:20 +0200
committerNick Mathewson <nickm@torproject.org>2014-07-15 15:42:20 +0200
commit8cc086059253347c82ebb1ff072abde56cd1da1a (patch)
tree833ea3cdf523b228eef7b77935d2d7b5f85f1765 /changes/curve25519-donna32-bug
parentf5ce580babc5ca8466da02c53669a58bde8f5445 (diff)
downloadtor-8cc086059253347c82ebb1ff072abde56cd1da1a.tar.gz
tor-8cc086059253347c82ebb1ff072abde56cd1da1a.zip
Update to latest curve25519-donna32
Diffstat (limited to 'changes/curve25519-donna32-bug')
-rw-r--r--changes/curve25519-donna32-bug10
1 files changed, 10 insertions, 0 deletions
diff --git a/changes/curve25519-donna32-bug b/changes/curve25519-donna32-bug
new file mode 100644
index 0000000000..54892d77aa
--- /dev/null
+++ b/changes/curve25519-donna32-bug
@@ -0,0 +1,10 @@
+ o Major bugfixes:
+
+ - Fix a bug in the bounds-checking in the 32-bit curve25519-donna
+ implementation that caused incorrect results on 32-bit
+ implementations when certain malformed inputs were used along with
+ a small class of private ntor keys. This bug does not currently
+ appear to allow an attacker to learn private keys or impersonate a
+ Tor server, but it could provide a means to distinguish 32-bit Tor
+ implementations from 64-bit Tor implementations.
+