CVE-2023-50981: High severity crypto++ vulnerability
Published Dec 18, 2023
·Updated
ModularSquareRoot in Crypto++ (aka cryptopp) through 8.9.0 allows attackers to cause a denial of service (infinite loop) via crafted DER public-key data associated with squared odd numbers, such as the square of 268995137513890432434389773128616504853.
Affected Software
1 affected component
Cryptopp Crypto\+\+<=8.9.0
Event History
Dec 18, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-50981?
CVE-2023-50981 is classified as a denial of service vulnerability.
2
How do I fix CVE-2023-50981?
To mitigate CVE-2023-50981, upgrade Crypto++ to version 8.9.1 or later.
3
What exploit does CVE-2023-50981 present?
CVE-2023-50981 allows attackers to cause an infinite loop through crafted DER public-key data.
4
Which versions of Crypto++ are affected by CVE-2023-50981?
CVE-2023-50981 affects Crypto++ versions up to and including 8.9.0.
5
What types of keys can trigger CVE-2023-50981?
CVE-2023-50981 can be triggered by squared odd number public keys.