Описание
gf2n.cpp in Crypto++ (aka cryptopp) through 8.9.0 allows attackers to cause a denial of service (application crash) via DER public-key data for an F(2^m) curve, if the degree of each term in the polynomial is not strictly decreasing.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| libcrypto++ | fixed | 8.9.0-2 | package | |
| libcrypto++ | ignored | bookworm | package | |
| libcrypto++ | no-dsa | bullseye | package | |
| libcrypto++ | no-dsa | buster | package |
Примечания
https://github.com/weidai11/cryptopp/issues/1248
https://github.com/weidai11/cryptopp/commit/641ae35258de397774744b8b17ef6632c3fa48b3
EPSS
Связанные уязвимости
gf2n.cpp in Crypto++ (aka cryptopp) through 8.9.0 allows attackers to cause a denial of service (application crash) via DER public-key data for an F(2^m) curve, if the degree of each term in the polynomial is not strictly decreasing.
gf2n.cpp in Crypto++ (aka cryptopp) through 8.9.0 allows attackers to cause a denial of service (application crash) via DER public-key data for an F(2^m) curve, if the degree of each term in the polynomial is not strictly decreasing.
gf2n.cpp in Crypto++ (aka cryptopp) through 8.9.0 allows attackers to cause a denial of service (application crash) via DER public-key data for an F(2^m) curve, if the degree of each term in the polynomial is not strictly decreasing.
EPSS