PT-2023-15850 · Crypto+++1 · Crypto+++1

Published

2023-08-22

·

Updated

2023-08-26

·

CVE-2022-48570

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Crypto++ versions prior to 8.5
Description The issue is related to a timing side channel in ECDSA signature generation. It is caused by the function FixedSizeAllocatorWithCleanup(), which could write to memory outside of the allocation if the allocated memory was not 16-byte aligned. This problem arose because a previous fix was intentionally removed for functionality reasons.
Recommendations For Crypto++ versions prior to 8.5, update to version 8.5 or later to resolve the issue.

Exploit

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-48570

Affected Products

Crypto++
Debian