Adopt ZIP 216: Require Canonical Jubjub Point Encodings #82
Labels
fix:vulnerability
Issues related to fix vulnerabilities of the architecture or software
team:Core
Low Level Core Development Team (Rust)
Jubjub was specified such that all points are strongly-typed with canonical representations. However, there is a bug in the version of the
jubjub
crate that you forked from, which allows non-canonical encodings to be silently accepted for two points:We are fixing this upstream in zkcrypto#46; I recommend that you similarly adopt ZIP 216 (or equivalent for your usages of Jubjub).
The text was updated successfully, but these errors were encountered: