CVE-2021-43398

CVE-2021-43398

Crypto++ (aka Cryptopp) 8.6.0 and earlier contains a timing leakage in MakePublicKey(). There is a clear correlation between execution time and private key length, which may cause disclosure of the length information of the private key. This might allow attackers to conduct timing attacks.

Source: CVE-2021-43398

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다