Nonce Increment Vulnerability in Rust's Snow Crate Affects TransportState
CVE-2024-58265
3.1LOW
What is CVE-2024-58265?
The Snow crate for Rust, prior to version 0.9.5, contains a vulnerability in its stateful TransportState implementation that allows an attacker to increment a nonce, potentially causing denial of message delivery. This flaw can disrupt communication by preventing legitimate messages from being processed, creating risks for applications relying on secure message transport.
Affected Version(s)
snow 0 < 0.9.5