Insecure temporary files In libcrypto++
Description
The InvertibleRWFunction::CalculateInverse function in rw.cpp in libcrypt++ 5.6.2 does not properly blind private key operations for the Rabin-Williams digital signature algorithm, which allows remote attackers to obtain private keys via a timing attack.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
debian 12 | 5.6.1-7 | ||
debian 14 | 5.6.1-7 | ||
debian 11 | 5.6.1-7 | ||
debian 13 | 5.6.1-7 |
Aliases
1. 2. 3. 4. 5.