{"id":"MGASA-2019-0362","summary":"Updated libcryptopp packages fix security vulnerability","details":"The updated packages fix a security vulnerability:\n\nCrypto++ 8.3.0 and earlier contains a timing side channel in ECDSA\nsignature generation. This allows a local or remote attacker, able to\nmeasure the duration of hundreds to thousands of signing operations,\nto compute the private key used. The issue occurs because scalar\nmultiplication in ecp.cpp (prime field curves, small leakage) and\nalgebra.cpp (binary field curves, large leakage) is not constant time\nand leaks the bit length of the scalar among other information\n(CVE-2019-14318).\n","modified":"2026-04-16T04:40:45.723237559Z","published":"2019-12-06T14:15:42Z","upstream":["CVE-2019-14318"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2019-0362.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=25759"},{"type":"WEB","url":"https://lists.opensuse.org/opensuse-updates/2019-08/msg00155.html"}],"affected":[{"package":{"name":"libcryptopp","ecosystem":"Mageia:7","purl":"pkg:rpm/mageia/libcryptopp?arch=source&distro=mageia-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.0.0-1.1.mga7"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2019-0362.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}