SimpleXMQ before 3.4.0, as used in SimpleX Chat before 4...
Moderate severity
Unreviewed
Published
Nov 13, 2022
to the GitHub Advisory Database
•
Updated Jan 28, 2023
Description
Published by the National Vulnerability Database
Nov 12, 2022
Published to the GitHub Advisory Database
Nov 13, 2022
Last updated
Jan 28, 2023
SimpleXMQ before 3.4.0, as used in SimpleX Chat before 4.2, does not apply a key derivation function to intended data, which can interfere with forward secrecy and can have other impacts if there is a compromise of a single private key. This occurs in the X3DH key exchange for the double ratchet protocol.
References