Resource management error in Crypto++ - CVE-2023-50980

 

Resource management error in Crypto++ - CVE-2023-50980

Published: December 21, 2023


Vulnerability identifier: #VU84651
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-50980
CWE-ID: CWE-399
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper management of internal resources within the application in gf2n.cpp. A remote attacker can cause a denial of service (application crash) via DER public-key data for an F(2^m) curve, if the degree of each term in the polynomial is not strictly decreasing.


Affected software

Crypto++
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
Basesystem Module
openSUSE Leap
Anolis OS
libcryptopp5_6_5-32bit-debuginfo
libcryptopp5_6_5-32bit
libcryptopp5_6_5-debuginfo
libcryptopp5_6_5
cryptopp
cryptopp-progs
cryptopp-devel
cryptopp-doc
libcryptopp-devel
libcryptopp8_6_0
libcryptopp8_6_0-debuginfo
libcryptopp-debugsource
libcryptopp8_6_0-32bit-debuginfo
libcryptopp8_6_0-32bit
libcryptopp8_6_0-64bit
libcryptopp8_6_0-64bit-debuginfo

How to mitigate CVE-2023-50980

Install updates from vendor's website.

libcryptopp5_6_5-32bit-debuginfo - update to 5.6.5-150000.1.9.1
libcryptopp5_6_5-32bit - update to 5.6.5-150000.1.9.1
libcryptopp5_6_5-debuginfo - update to 5.6.5-150000.1.9.1
libcryptopp5_6_5 - update to 5.6.5-150000.1.9.1
cryptopp - update to 8.2.0-2.3
cryptopp-progs - update to 8.2.0-2.3
cryptopp-devel - update to 8.2.0-2.3
cryptopp-doc - update to 8.2.0-2.3
libcryptopp-devel - update to 8.6.0-150400.3.3.1
libcryptopp8_6_0 - update to 8.6.0-150400.3.3.1
libcryptopp8_6_0-debuginfo - update to 8.6.0-150400.3.3.1
libcryptopp-debugsource - update to 8.6.0-150400.3.3.1
libcryptopp8_6_0-32bit-debuginfo - update to 8.6.0-150400.3.3.1
libcryptopp8_6_0-32bit - update to 8.6.0-150400.3.3.1
libcryptopp8_6_0-64bit - update to 8.6.0-150400.3.3.1
libcryptopp8_6_0-64bit-debuginfo - update to 8.6.0-150400.3.3.1

External References

Related Security Bulletins