CVE-2021-43398 - log back

CVE-2021-43398 edited at 05 Nov 2021 10:43:42
Severity
- Unknown
+ Medium
Remote
- Unknown
+ Remote
Type
- Unknown
+ Private key recovery
Description
+ Crypto++ 8.6.0 and earlier contains a timing leakage in MakePublicKey(). There is a clear correlation between execution time and private key length, which may cause disclosure of the length information of the private key. This might allow attackers to conduct timing attacks.
References
+ https://github.com/weidai11/cryptopp/issues/1080
Notes
CVE-2021-43398 created at 05 Nov 2021 10:42:46