CVE Vulnerabilities

CVE-2023-50980

Published: Dec 18, 2023 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

gf2n.cpp in Crypto++ (aka cryptopp) through 8.9.0 allows attackers to cause a denial of service (application crash) via DER public-key data for an F(2^m) curve, if the degree of each term in the polynomial is not strictly decreasing.

Affected Software

NameVendorStart VersionEnd Version
Crypto++Cryptopp*8.9.0 (including)
Libcrypto++Ubuntubionic*
Libcrypto++Ubuntufocal*
Libcrypto++Ubuntulunar*
Libcrypto++Ubuntumantic*
Libcrypto++Ubuntuoracular*
Libcrypto++Ubuntuplucky*
Libcrypto++Ubuntutrusty*
Libcrypto++Ubuntutrusty/esm*
Libcrypto++Ubuntuxenial*

References