The InvertibleRWFunction::CalculateInverse function in rw.cpp in libcrypt++ 5.6.2 does not properly blind private key operations for the Rabin-Williams digital signature algorithm, which allows remote attackers to obtain private keys via a timing attack.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade libcrypto++ | Jul 30, 2024 | Jul 1, 2015 |
| Freebsd | — | Upgrade cryptopp | Dec 10, 2025 | Dec 6, 2016 |
| Suse | — | Upgrade libcryptopp-develUpgrade libcryptopp5_6_5 | Dec 18, 2015 | Jul 1, 2015 |
| Ubuntu | — | Upgrade libcrypto++ | Nov 19, 2024 | Jul 1, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub