{"id":"GHSA-h864-m8vm-3xvj","summary":"oqs's Post-Quantum Signature scheme Rainbow level I parametersets broken","details":"Ward Beullens found a practical key-recovery attack against Rainbow.\nThe level I parametersets are removed from liboqs starting from version `0.7.2`.\nFind the scientific details in [Breaking Rainbow Takes a Weekend on a Laptop](https://eprint.iacr.org/2022/214).\n\nThis means all the `oqs::sig::Algorithm::RainbowI*` variants are insecure.\n","aliases":["RUSTSEC-2022-0047"],"modified":"2023-11-08T04:19:57.153953Z","published":"2022-08-18T19:06:39Z","database_specific":{"cwe_ids":[],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2022-08-18T19:06:39Z","nvd_published_at":null},"references":[{"type":"PACKAGE","url":"https://github.com/open-quantum-safe/liboqs-rust"},{"type":"WEB","url":"https://groups.google.com/a/list.nist.gov/g/pqc-forum/c/KFgw5_qCXiI?pli=1"},{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2022-0047.html"}],"affected":[{"package":{"name":"oqs","ecosystem":"crates.io","purl":"pkg:cargo/oqs"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.7.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/08/GHSA-h864-m8vm-3xvj/GHSA-h864-m8vm-3xvj.json"}}],"schema_version":"1.9.0"}