The InvertibleRWFunction::CalculateInverse function in rw.cpp in libcrypt++ 5.6.2 does not properly blind private key operations for the Rabin-Williams digital signature algorithm, which allows remote attackers to obtain private keys via a timing attack.
{
"binaries": [
{
"binary_name": "libcrypto++-dev",
"binary_version": "5.6.1-6+deb8u1build0.14.04.1"
},
{
"binary_name": "libcrypto++-utils",
"binary_version": "5.6.1-6+deb8u1build0.14.04.1"
},
{
"binary_name": "libcrypto++9",
"binary_version": "5.6.1-6+deb8u1build0.14.04.1"
}
],
"availability": "No subscription required"
}