CVE-2019-14318
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Crypto++ 8.3.0 and earlier contains a timing side channel in ECDSA signature generation. This allows a local or remote attacker, able to measure the duration of hundreds to thousands of signing operations, to compute the private key used. The issue occurs because scalar multiplication in ecp.cpp (prime field curves, small leakage) and algebra.cpp (binary field curves, large leakage) is not constant time and leaks the bit length of the scalar among other information.
Crypto++ versión 8.3.0 y anterior, contiene un canal lateral de sincronización en la generación de firmas ECDSA. Esto permite a un atacante local o remoto, capaz de medir la duración de cientos a miles de operaciones de firma, calcular la clave privada utilizada. El problema se produce porque la multiplicación de scalar en el archivo ecp.cpp (curvas del campo principal, fugas pequeñas) y el archivo algebra.cpp (curvas del campo binario, fugas grandes) no son de tiempo constante y filtra la longitud de bits del scalar entre otra información.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-07-27 CVE Reserved
- 2019-07-30 CVE Published
- 2024-07-23 EPSS Updated
- 2024-08-05 CVE Updated
- 2024-08-05 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-417: Communication Channel Errors
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
http://www.openwall.com/lists/oss-security/2019/10/02/2 | Mailing List | |
https://minerva.crocs.fi.muni.cz | X_refsource_misc | |
https://tches.iacr.org/index.php/TCHES/article/view/7337 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://eprint.iacr.org/2011/232.pdf | 2024-08-05 |
URL | Date | SRC |
---|---|---|
https://github.com/weidai11/cryptopp/issues/869 | 2019-08-20 |
URL | Date | SRC |
---|---|---|
http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00066.html | 2019-08-20 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cryptopp Search vendor "Cryptopp" | Crypto\+\+ Search vendor "Cryptopp" for product "Crypto\+\+" | <= 8.3.0 Search vendor "Cryptopp" for product "Crypto\+\+" and version " <= 8.3.0" | - |
Affected
|