A flaw has been found in editso fuso up to 1.0.4-beta.7. This affects the function PenetrateRsaAndAesHandshake of the file src/net/penetrate/handshake/mod.rs. This manipulation of the argument priv_key causes inadequate encryption strength. Remote exploitation of the attack is possible. A high degree of complexity is needed for the attack. The exploitability is reported as difficult.
Weaknesses in this category are related to the design and implementation of data confidentiality and integrity. Frequently these deal with the use of encoding techniques, encryption libraries, and hashing algorithms. The weaknesses in this category could lead to a degradation of the quality data if they are not addressed.
Link | Tags |
---|---|
https://vuldb.com/?id.321506 | technical description vdb entry |
https://vuldb.com/?ctiid.321506 | signature permissions required |
https://vuldb.com/?submit.635449 | third party advisory |
https://chatgpt.com/share/68ae1bfa-8cd4-8005-8add-969bc42047b4 | related |