Infinite loop in Crypto++ - CVE-2023-50981

 

Infinite loop in Crypto++ - CVE-2023-50981

Published: December 21, 2023


Vulnerability identifier: #VU84653
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-50981
CWE-ID: CWE-835
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to infinite loop in ModularSquareRoot. A remote attacker can consume all available system resources and cause denial of service conditions via crafted DER public-key data associated with squared odd numbers, such as the square of 268995137513890432434389773128616504853.


Affected software

Crypto++
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
Basesystem Module
openSUSE Leap
Anolis OS
cryptopp
cryptopp-progs
cryptopp-devel
cryptopp-doc
libcryptopp8_6_0-debuginfo
libcryptopp8_6_0
libcryptopp-debugsource
libcryptopp-devel
libcryptopp8_6_0-32bit
libcryptopp8_6_0-32bit-debuginfo
libcryptopp8_6_0-64bit
libcryptopp8_6_0-64bit-debuginfo

How to mitigate CVE-2023-50981

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

cryptopp - update to 8.2.0-2.3
cryptopp-progs - update to 8.2.0-2.3
cryptopp-devel - update to 8.2.0-2.3
cryptopp-doc - update to 8.2.0-2.3
libcryptopp8_6_0-debuginfo - update to 8.6.0-150400.3.6.1
libcryptopp8_6_0 - update to 8.6.0-150400.3.6.1
libcryptopp-debugsource - update to 8.6.0-150400.3.6.1
libcryptopp-devel - update to 8.6.0-150400.3.6.1
libcryptopp8_6_0-32bit - update to 8.6.0-150400.3.6.1
libcryptopp8_6_0-32bit-debuginfo - update to 8.6.0-150400.3.6.1
libcryptopp8_6_0-64bit - update to 8.6.0-150400.3.6.1
libcryptopp8_6_0-64bit-debuginfo - update to 8.6.0-150400.3.6.1

External References

Related Security Bulletins