From URL: ---- The InvertibleRWFunction::CalculateInverse function in rw.cpp in libcrypt++ 5.6.2 does not properly blind private key operations for the Rabin-Williams digital signature algorithm, which allows remote attackers to obtain private keys via a timing attack. ---- https://github.com/weidai11/cryptopp/commit/9425e16437439e68c7d96abef922167d68fafaff http://sourceforge.net/p/cryptopp/code/542/ Reproducible: Always
added: crypto++-5.6.2-r2
@Maintainers: is -r2 ready for stabilisation?
(In reply to stanley - Security Padawan from comment #3) > @Maintainers: is -r2 ready for stabilisation? r2 differs from r1 only by the fix for this CVE. feel free to stabilize.
Stable for HPPA PPC64.
amd64 stable
x86 stable
Stable on alpha.
ppc stable
sparc stable. Maintainer(s), please cleanup. Security, please vote.
Vulnerable removed.
Vote: no.
GLSA Vote: No