Information on source package libcrypto++

Available versions

ReleaseVersion
jessie5.6.1-6+deb8u3
stretch5.6.4-7
buster5.6.4-8
bullseye8.4.0-1
bookworm8.7.0+git220824-1
trixie8.9.0-1.1
sid8.9.0-1.1

Open issues

BugjessiestretchbusterbullseyebookwormtrixiesidDescription
CVE-2024-28285vulnerablevulnerable (no DSA, postponed)vulnerable (no DSA, postponed)vulnerable (no DSA)vulnerable (no DSA, postponed)vulnerablevulnerableA Fault Injection vulnerability in the SymmetricDecrypt function in cr ...
CVE-2023-50981vulnerablevulnerable (no DSA)vulnerable (no DSA)vulnerable (no DSA)vulnerable (no DSA, postponed)vulnerablevulnerableModularSquareRoot in Crypto++ (aka cryptopp) through 8.9.0 allows atta ...
CVE-2023-50980vulnerablevulnerable (no DSA)vulnerable (no DSA)vulnerable (no DSA)vulnerable (no DSA, ignored)vulnerablevulnerablegf2n.cpp in Crypto++ (aka cryptopp) through 8.9.0 allows attackers to ...
CVE-2023-50979vulnerablevulnerable (no DSA)vulnerable (no DSA)vulnerable (no DSA)vulnerable (no DSA, postponed)vulnerablevulnerableCrypto++ (aka cryptopp) through 8.9.0 has a Marvin side channel during ...
CVE-2022-48570vulnerablevulnerable (no DSA)vulnerable (no DSA)vulnerable (no DSA)vulnerable (no DSA, postponed)vulnerablevulnerableCrypto++ through 8.4 contains a timing side channel in ECDSA signature ...
CVE-2021-43398vulnerableunknownunknownunknownunknownunknownunknownCrypto++ (aka Cryptopp) 8.6.0 and earlier contains a timing leakage in ...
CVE-2021-40530vulnerablevulnerable (no DSA)vulnerable (no DSA)vulnerable (no DSA)fixedfixedfixedThe ElGamal implementation in Crypto++ through 8.5 allows plaintext re ...
CVE-2019-14318vulnerable (no DSA)vulnerable (no DSA)vulnerable (no DSA)fixedfixedfixedfixedCrypto++ 8.3.0 and earlier contains a timing side channel in ECDSA sig ...
CVE-2017-9434vulnerable (no DSA)fixedfixedfixedfixedfixedfixedCrypto++ (aka cryptopp) through 5.6.5 contains an out-of-bounds read v ...

Open unimportant issues

BugjessiestretchbusterbullseyebookwormtrixiesidDescription
CVE-2016-7420vulnerablevulnerablevulnerablevulnerablevulnerablevulnerablevulnerableCrypto++ (aka cryptopp) through 5.6.4 does not document the requiremen ...

Resolved issues

BugDescription
CVE-2016-9939Crypto++ (aka cryptopp and libcrypto++) 5.6.4 contained a bug in its A ...
CVE-2016-7544Crypto++ 5.6.4 incorrectly uses Microsoft's stack-based _malloca and _ ...
CVE-2016-3995The timing attack protection in Rijndael::Enc::ProcessAndXorBlock and ...
CVE-2015-2141The InvertibleRWFunction::CalculateInverse function in rw.cpp in libcr ...

Security announcements

DSA / DLADescription
DLA-766-1libcrypto++ - security update
DSA-3748-1libcrypto++ - security update
DLA-262-1libcrypto++ - security update
DSA-3296-1libcrypto++ - security update

Search for package or bug name: Reporting problems