Crypto Cryptopp Crypto

Do you want an email whenever new security vulnerabilities are reported in Cryptopp Crypto?

By the Year

In 2021 there have been 2 vulnerabilities in Cryptopp Crypto with an average score of 5.6 out of ten. Crypto did not have any published security vulnerabilities last year. That is, 2 more vulnerabilities have already been reported in 2021 as compared to last year.

Year Vulnerabilities Average Score
2021 2 5.60
2020 0 0.00
2019 1 5.90
2018 0 0.00

It may take a day or so for new Crypto vulnerabilities to show up in the stats or in the list of recent security vulnerabilties. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Cryptopp Crypto Security Vulnerabilities

Crypto++ (aka Cryptopp) 8.6.0 and earlier contains a timing leakage in MakePublicKey()

CVE-2021-43398 5.3 - Medium - November 04, 2021

Crypto++ (aka Cryptopp) 8.6.0 and earlier contains a timing leakage in MakePublicKey(). There is a clear correlation between execution time and private key length, which may cause disclosure of the length information of the private key. This might allow attackers to conduct timing attacks.

Side Channel Attack

The ElGamal implementation in Crypto++ through 8.5

CVE-2021-40530 5.9 - Medium - September 06, 2021

The ElGamal implementation in Crypto++ through 8.5 allows plaintext recovery because, during interaction between two cryptographic libraries, a certain dangerous combination of the prime defined by the receiver's public key, the generator defined by the receiver's public key, and the sender's ephemeral exponents can lead to a cross-configuration attack against OpenPGP.

Use of a Broken or Risky Cryptographic Algorithm

Crypto++ 8.3.0 and earlier contains a timing side channel in ECDSA signature generation

CVE-2019-14318 5.9 - Medium - July 30, 2019

Crypto++ 8.3.0 and earlier contains a timing side channel in ECDSA signature generation. This allows a local or remote attacker, able to measure the duration of hundreds to thousands of signing operations, to compute the private key used. The issue occurs because scalar multiplication in ecp.cpp (prime field curves, small leakage) and algebra.cpp (binary field curves, large leakage) is not constant time and leaks the bit length of the scalar among other information.

Communication Channel Errors

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Cryptopp Crypto or by Cryptopp? Click the Watch button to subscribe.

Cryptopp
Vendor

subscribe