gf2n.cpp in Crypto++ (aka cryptopp) through 8.9.0 allows attackers to cause a denial of service (application crash) via DER public-key data for an F(2^m) curve, if the degree of each term in the polynomial is not strictly decreasing.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade libcrypto++No solution exists | May 15, 2025 | Dec 18, 2023 |
| Suse | — | Upgrade libcryptopp8_6_0-32bitUpgrade libcryptopp8_6_0Upgrade libcryptopp5_6_5-32bitUpgrade libcryptopp-develUpgrade libcryptopp5_6_5 | Dec 22, 2023 | Dec 18, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub