aboutsummaryrefslogtreecommitdiff
path: root/changes/curve25519-donna32-bug
blob: 7fccab1b0cd5d18988432318447da9d9f0422c54 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
  o Major bugfixes:

    - Fix a bug in the bounds-checking in the 32-bit curve25519-donna
      implementation that caused incorrect results on 32-bit
      implementations when certain malformed inputs were used along with
      a small class of private ntor keys. This bug does not currently
      appear to allow an attacker to learn private keys or impersonate a
      Tor server, but it could provide a means to distinguish 32-bit Tor
      implementations from 64-bit Tor implementations. Fixes bug 12694;
      bugfix on 0.2.4.8-alpha. Bug found by Robert Ransom; fix from
      Adam Langley.