Vulnerability Details CVE-2023-50980
gf2n.cpp in Crypto++ (aka cryptopp) through 8.9.0 allows attackers to cause a denial of service (application crash) via DER public-key data for an F(2^m) curve, if the degree of each term in the polynomial is not strictly decreasing.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 28.3%
CVSS Severity
CVSS v3 Score 7.5
Products affected by CVE-2023-50980
-
cpe:2.3:a:cryptopp:crypto++:5.0
-
cpe:2.3:a:cryptopp:crypto++:5.1
-
cpe:2.3:a:cryptopp:crypto++:5.2
-
cpe:2.3:a:cryptopp:crypto++:5.2.1
-
cpe:2.3:a:cryptopp:crypto++:5.2.3
-
cpe:2.3:a:cryptopp:crypto++:5.3.0
-
cpe:2.3:a:cryptopp:crypto++:5.4
-
cpe:2.3:a:cryptopp:crypto++:5.5
-
cpe:2.3:a:cryptopp:crypto++:5.5.1
-
cpe:2.3:a:cryptopp:crypto++:5.5.2
-
cpe:2.3:a:cryptopp:crypto++:5.6.0
-
cpe:2.3:a:cryptopp:crypto++:5.6.1
-
cpe:2.3:a:cryptopp:crypto++:5.6.2
-
cpe:2.3:a:cryptopp:crypto++:5.6.3
-
cpe:2.3:a:cryptopp:crypto++:5.6.4
-
cpe:2.3:a:cryptopp:crypto++:5.6.5
-
cpe:2.3:a:cryptopp:crypto++:6.0.0
-
cpe:2.3:a:cryptopp:crypto++:6.1.0
-
cpe:2.3:a:cryptopp:crypto++:7.0.0
-
cpe:2.3:a:cryptopp:crypto++:8.0.0
-
cpe:2.3:a:cryptopp:crypto++:8.1.0
-
cpe:2.3:a:cryptopp:crypto++:8.2.0
-
cpe:2.3:a:cryptopp:crypto++:8.3.0
-
cpe:2.3:a:cryptopp:crypto++:8.4.0
-
cpe:2.3:a:cryptopp:crypto++:8.5.0
-
cpe:2.3:a:cryptopp:crypto++:8.6.0
-
cpe:2.3:a:cryptopp:crypto++:8.7.0
-
cpe:2.3:a:cryptopp:crypto++:8.8.0
-
cpe:2.3:a:cryptopp:crypto++:8.9.0