The snow crate before 0.9.5 for Rust, when stateful TransportState is used, allows incrementing a nonce and thereby denying message delivery.
The product stores security-critical state information about its users, or the product itself, in a location that is accessible to unauthorized actors.
Link | Tags |
---|---|
https://rustsec.org/advisories/RUSTSEC-2024-0011.html | third party advisory |
https://github.com/mcginty/snow/security/advisories/GHSA-7g9j-g5jg-3vv3 | vendor advisory |
https://crates.io/crates/snow | product |