MGASA-2016-0147

Source
https://advisories.mageia.org/MGASA-2016-0147.html
Import Source
https://advisories.mageia.org/MGASA-2016-0147.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2016-0147
Related
Published
2016-04-25T07:57:21Z
Modified
2016-04-25T07:50:07Z
Summary
Updated libcryptopp packages fix CVE-2016-3995
Details

Updated libcryptopp packages fix security vulnerability:

In libcryptopp, for both Rijndael::Enc::ProcessAndXorBlock and Rijndael::Dec::ProcessAndXorBlock there is some code to avoid timing attacks, however it is removed by the compiler due to optimizations, making the binary vulnerable to timing attacks (CVE-2016-3995).

This update also corrects some bugs with the package.

References
Credits

Affected packages

Mageia:5 / libcryptopp

Package

Name
libcryptopp
Purl
pkg:rpm/mageia/libcryptopp?arch=source&distro=mageia-5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.6.3-1.1.mga5

Ecosystem specific

{
    "section": "core"
}