| Release | Version |
|---|---|
| bullseye | 8.4.0-1 |
| bookworm | 8.7.0+git220824-1 |
| trixie | 8.9.0-2 |
| forky | 8.9.0-2 |
| sid | 8.9.0-2 |
| Bug | bullseye | bookworm | trixie | forky | sid | Description |
|---|---|---|---|---|---|---|
| CVE-2024-28285 | vulnerable (no DSA) | vulnerable (no DSA, postponed) | vulnerable (no DSA, postponed) | vulnerable | vulnerable | A Fault Injection vulnerability in the SymmetricDecrypt function in cr ... |
| CVE-2023-50981 | vulnerable (no DSA) | vulnerable (no DSA, postponed) | vulnerable (no DSA, postponed) | vulnerable | vulnerable | ModularSquareRoot in Crypto++ (aka cryptopp) through 8.9.0 allows atta ... |
| CVE-2023-50980 | vulnerable (no DSA) | vulnerable (no DSA, ignored) | fixed | fixed | fixed | gf2n.cpp in Crypto++ (aka cryptopp) through 8.9.0 allows attackers to ... |
| CVE-2023-50979 | vulnerable (no DSA) | vulnerable (no DSA, postponed) | vulnerable (no DSA, postponed) | vulnerable | vulnerable | Crypto++ (aka cryptopp) through 8.9.0 has a Marvin side channel during ... |
| CVE-2022-48570 | vulnerable (no DSA) | vulnerable (no DSA, postponed) | vulnerable (no DSA, postponed) | vulnerable | vulnerable | Crypto++ through 8.4 contains a timing side channel in ECDSA signature ... |
| CVE-2021-40530 | vulnerable (no DSA) | fixed | fixed | fixed | fixed | The ElGamal implementation in Crypto++ through 8.5 allows plaintext re ... |
| Bug | bullseye | bookworm | trixie | forky | sid | Description |
|---|---|---|---|---|---|---|
| CVE-2016-7420 | vulnerable | vulnerable | vulnerable | vulnerable | vulnerable | Crypto++ (aka cryptopp) through 5.6.4 does not document the requiremen ... |
| Bug | Description |
|---|---|
| CVE-2019-14318 | Crypto++ 8.3.0 and earlier contains a timing side channel in ECDSA sig ... |
| CVE-2017-9434 | Crypto++ (aka cryptopp) through 5.6.5 contains an out-of-bounds read v ... |
| CVE-2016-9939 | Crypto++ (aka cryptopp and libcrypto++) 5.6.4 contained a bug in its A ... |
| CVE-2016-7544 | Crypto++ 5.6.4 incorrectly uses Microsoft's stack-based _malloca and _ ... |
| CVE-2016-3995 | The timing attack protection in Rijndael::Enc::ProcessAndXorBlock and ... |
| CVE-2015-2141 | The InvertibleRWFunction::CalculateInverse function in rw.cpp in libcr ... |
| DSA / DLA | Description |
|---|---|
| DLA-766-1 | libcrypto++ - security update |
| DSA-3748-1 | libcrypto++ - security update |
| DLA-262-1 | libcrypto++ - security update |
| DSA-3296-1 | libcrypto++ - security update |