MGASA-2019-0362 - Updated libcryptopp packages fix security vulnerability

Publication date: 06 Dec 2019
URL: https://advisories.mageia.org/MGASA-2019-0362.html
Type: security
Affected Mageia releases: 7
CVE: CVE-2019-14318

The updated packages fix a security vulnerability:

Crypto++ 8.3.0 and earlier contains a timing side channel in ECDSA
signature generation. This allows a local or remote attacker, able to
measure the duration of hundreds to thousands of signing operations,
to compute the private key used. The issue occurs because scalar
multiplication in ecp.cpp (prime field curves, small leakage) and
algebra.cpp (binary field curves, large leakage) is not constant time
and leaks the bit length of the scalar among other information
(CVE-2019-14318).

References:
- https://bugs.mageia.org/show_bug.cgi?id=25759
- - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14318

SRPMS:
- 7/core/libcryptopp-7.0.0-1.1.mga7

Mageia 2019-0362: libcryptopp security update

The updated packages fix a security vulnerability: Crypto++ 8.3.0 and earlier contains a timing side channel in ECDSA signature generation

Summary

The updated packages fix a security vulnerability:
Crypto++ 8.3.0 and earlier contains a timing side channel in ECDSA signature generation. This allows a local or remote attacker, able to measure the duration of hundreds to thousands of signing operations, to compute the private key used. The issue occurs because scalar multiplication in ecp.cpp (prime field curves, small leakage) and algebra.cpp (binary field curves, large leakage) is not constant time and leaks the bit length of the scalar among other information (CVE-2019-14318).

References

- https://bugs.mageia.org/show_bug.cgi?id=25759

- - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14318

Resolution

MGASA-2019-0362 - Updated libcryptopp packages fix security vulnerability

SRPMS

- 7/core/libcryptopp-7.0.0-1.1.mga7

Severity
Publication date: 06 Dec 2019
URL: https://advisories.mageia.org/MGASA-2019-0362.html
Type: security
CVE: CVE-2019-14318

Related News