All errata/sisyphus/ALT-PU-2017-2781-1
ALT-PU-2017-2781-1

Package update libcryptopp in branch sisyphus

Version5.6.5-alt1
Published2017-12-10
Max severityHIGH
Severity:

Closed issues (3)

CVE-2016-3995
HIGH7.5

The timing attack protection in Rijndael::Enc::ProcessAndXorBlock and Rijndael::Dec::ProcessAndXorBlock in Crypto++ (aka cryptopp) before 5.6.4 may be optimized out by the compiler, which allows attackers to conduct timing attacks.

Published: 2017-02-13Modified: 2025-04-20
CVSS 2.0MEDIUM 5.0
CVSS:2.0/AV:N/AC:L/Au:N/C:P/I:N/A:N
CVSS 3.xHIGH 7.5
CVSS:3.x/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N