CVE-2015-2141
Publication date 1 July 2015
Last updated 24 July 2024
Ubuntu priority
Description
The InvertibleRWFunction::CalculateInverse function in rw.cpp in libcrypt++ 5.6.2 does not properly blind private key operations for the Rabin-Williams digital signature algorithm, which allows remote attackers to obtain private keys via a timing attack.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| libcrypto++ | ||
| 16.04 LTS xenial |
Not affected
|
|
| 14.04 LTS trusty |
Fixed 5.6.1-6+deb8u1build0.14.04.1
|
|