Bugzilla – Bug 1224280
VUL-0: CVE-2024-28285: libcryptopp: potential leak of secret key of ElGamal encryption via fault injection
Last modified: 2024-06-26 10:20:37 UTC
A Fault Injection vulnerability in the SymmetricDecrypt function in cryptopp/elgamal.h of Cryptopp Crypto++ 8.9, allows an attacker to co-reside in the same system with a victim process to disclose information and escalate privileges. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-28285 https://www.cve.org/CVERecord?id=CVE-2024-28285 https://gist.github.com/liang-junkai/3e91f58070812ea76c1b8c126c3e28c7 https://bugzilla.redhat.com/show_bug.cgi?id=2280418
https://github.com/weidai11/cryptopp/issues/1262 No news upstream.
Reassigning to current maintainer. Thanks Pedro