CVE-2023-50980: High severity crypto++ vulnerability
gf2n.cpp in Crypto++ (aka cryptopp) through 8.9.0 allows attackers to cause a denial of service (application crash) via DER public-key data for an F(2^m) curve, if the degree of each term in the polynomial is not strictly decreasing.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-50980?
CVE-2023-50980 has a severity rating that indicates it can cause denial of service through application crashes.
How do I fix CVE-2023-50980?
To mitigate CVE-2023-50980, upgrade Crypto++ to version 8.9.1 or later, which addresses this vulnerability.
What impact does CVE-2023-50980 have on Crypto++ applications?
CVE-2023-50980 can lead to application crashes when handling improperly structured DER public-key data for certain F(2^m) curves.
Which versions of Crypto++ are affected by CVE-2023-50980?
CVE-2023-50980 affects Crypto++ versions up to and including 8.9.0.
Is there a known exploit for CVE-2023-50980?
There is currently no publicly available exploit specifically for CVE-2023-50980, but it poses a risk of denial of service.