CVE-2022-45195
EUVD-2022-4810312.11.2022, 19:15
SimpleXMQ before 3.4.0, as used in SimpleX Chat before 4.2, does not apply a key derivation function to intended data, which can interfere with forward secrecy and can have other impacts if there is a compromise of a single private key. This occurs in the X3DH key exchange for the double ratchet protocol.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| simplex | simplex_chat | 𝑥 < 4.2 |
| simplex | simplexmq | 𝑥 < 3.4.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References