Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Plestrin

#35800de 53,634
7.5CVSS total
Vulnerabilidades · 1
PT-2017-8437
7.5
2016-04-25
Cryptopp · Crypto++ · CVE-2016-3995
**Name of the Vulnerable Software and Affected Versions** Crypto++ versions prior to 5.6.4 **Description** The issue concerns the timing attack protection in the Rijndael encryption and decryption processes. Specifically, the `Rijndael::Enc::ProcessAndXorBlock` and `Rijndael::Dec::ProcessAndXorBlock` functions may have their timing attack protection optimized out by the compiler. This optimization could allow attackers to conduct timing attacks. **Recommendations** For versions prior to 5.6.4, update to version 5.6.4 or later to resolve the issue.