Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Crypto++ through 8.4 contains a timing side channel in ECDSA signature generation. Function FixedSizeAllocatorWithCleanup could write to memory outside of the allocation if the allocated memory was not 16-byte aligned. NOTE: this issue exists because the CVE-2019-14318 fix was intentionally removed for functionality reasons.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Crypto++ 缓冲区错误漏洞
Vulnerability Description
Crypto++是一款C++加密方法类库 Crypto++ 8.4及之前版本存在安全漏洞,该漏洞源于若分配的内存不是16字节对齐的,函数 FixSizeAllocatorWithCleanup可能会写入分配之外的内存。
CVSS Information
N/A
Vulnerability Type
N/A