Lucene search

K
debianDebianDEBIAN:DLA-262-1:F168E
HistoryJun 30, 2015 - 8:47 p.m.

[SECURITY] [DLA 262-1] libcrypto++ security update

2015-06-3020:47:22
lists.debian.org
10

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

7.4

Confidence

High

EPSS

0.004

Percentile

72.4%

Package : libcrypto++
Version : 5.6.0-6+deb6u1
CVE ID : CVE-2015-2141

Evgeny Sidorov discovered that libcrypto++, a general purpose C++
cryptographic library, did not properly implement blinding to mask
private key operations for the Rabin-Williams digital signature
algorithm. This could allow remote attackers to mount a timing attack
and retrieve the user's private key.

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

7.4

Confidence

High

EPSS

0.004

Percentile

72.4%