CVE-2015-2141: Infoleak
Published Jul 1, 2015
·Updated
The InvertibleRWFunction::CalculateInverse function in rw.cpp in libcrypt++ 5.6.2 does not properly blind private key operations for the Rabin-Williams digital signature algorithm, which allows remote attackers to obtain private keys via a timing attack.
Affected Software
3 affected components
Cryptopp Crypto\+\+ Library=5.6.2
openSUSE openSUSE=13.1
openSUSE openSUSE=13.2
Event History
Jul 1, 2015
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-2141?
CVE-2015-2141 is classified as a high severity vulnerability due to potential exposure of private keys.
2
How do I fix CVE-2015-2141?
To mitigate CVE-2015-2141, update libcrypt++ to a version that has addressed this timing attack issue.
3
What software versions are affected by CVE-2015-2141?
CVE-2015-2141 affects Crypto++ Library version 5.6.2 and specific versions of SUSE Linux.
4
What type of attack does CVE-2015-2141 enable?
CVE-2015-2141 allows remote attackers to use timing attacks to obtain private keys.
5
Is CVE-2015-2141 related to any specific cryptographic algorithms?
Yes, CVE-2015-2141 is associated with the Rabin-Williams digital signature algorithm.