Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Crypto++ 8.3.0 and earlier contains a timing side channel in ECDSA signature generation. This allows a local or remote attacker, able to measure the duration of hundreds to thousands of signing operations, to compute the private key used. The issue occurs because scalar multiplication in ecp.cpp (prime field curves, small leakage) and algebra.cpp (binary field curves, large leakage) is not constant time and leaks the bit length of the scalar among other information.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Crypto++ 代码问题漏洞
Vulnerability Description
Crypto++是一款C++加密方法类库 Crypto++ 8.3.0及之前版本中存在安全漏洞。攻击者可利用该漏洞计算所使用的私钥。
CVSS Information
N/A
Vulnerability Type
N/A