Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-3995

Опубликовано: 13 фев. 2017
Источник: debian

Описание

The timing attack protection in Rijndael::Enc::ProcessAndXorBlock and Rijndael::Dec::ProcessAndXorBlock in Crypto++ (aka cryptopp) before 5.6.4 may be optimized out by the compiler, which allows attackers to conduct timing attacks.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libcrypto++fixed5.6.3-6package
libcrypto++fixed5.6.1-6+deb8u2jessiepackage
libcrypto++fixed5.6.1-6+deb7u2wheezypackage

Примечания

  • https://github.com/weidai11/cryptopp/issues/146

  • https://www.openwall.com/lists/oss-security/2016/04/10/6

  • Initial upload in 5.6.3-5 was incomplete

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 9 лет назад

The timing attack protection in Rijndael::Enc::ProcessAndXorBlock and Rijndael::Dec::ProcessAndXorBlock in Crypto++ (aka cryptopp) before 5.6.4 may be optimized out by the compiler, which allows attackers to conduct timing attacks.

CVSS3: 7.5
nvd
почти 9 лет назад

The timing attack protection in Rijndael::Enc::ProcessAndXorBlock and Rijndael::Dec::ProcessAndXorBlock in Crypto++ (aka cryptopp) before 5.6.4 may be optimized out by the compiler, which allows attackers to conduct timing attacks.

CVSS3: 7.5
github
больше 3 лет назад

The timing attack protection in Rijndael::Enc::ProcessAndXorBlock and Rijndael::Dec::ProcessAndXorBlock in Crypto++ (aka cryptopp) before 5.6.4 may be optimized out by the compiler, which allows attackers to conduct timing attacks.