Vulnerability Details CVE-2023-50981
ModularSquareRoot in Crypto++ (aka cryptopp) through 8.9.0 allows attackers to cause a denial of service (infinite loop) via crafted DER public-key data associated with squared odd numbers, such as the square of 268995137513890432434389773128616504853.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 23.1%
CVSS Severity
CVSS v3 Score 7.5
Products affected by CVE-2023-50981
-
cpe:2.3:a:cryptopp:crypto++:5.0
-
cpe:2.3:a:cryptopp:crypto++:5.1
-
cpe:2.3:a:cryptopp:crypto++:5.2
-
cpe:2.3:a:cryptopp:crypto++:5.2.1
-
cpe:2.3:a:cryptopp:crypto++:5.2.3
-
cpe:2.3:a:cryptopp:crypto++:5.3.0
-
cpe:2.3:a:cryptopp:crypto++:5.4
-
cpe:2.3:a:cryptopp:crypto++:5.5
-
cpe:2.3:a:cryptopp:crypto++:5.5.1
-
cpe:2.3:a:cryptopp:crypto++:5.5.2
-
cpe:2.3:a:cryptopp:crypto++:5.6.0
-
cpe:2.3:a:cryptopp:crypto++:5.6.1
-
cpe:2.3:a:cryptopp:crypto++:5.6.2
-
cpe:2.3:a:cryptopp:crypto++:5.6.3
-
cpe:2.3:a:cryptopp:crypto++:5.6.4
-
cpe:2.3:a:cryptopp:crypto++:5.6.5
-
cpe:2.3:a:cryptopp:crypto++:6.0.0
-
cpe:2.3:a:cryptopp:crypto++:6.1.0
-
cpe:2.3:a:cryptopp:crypto++:7.0.0
-
cpe:2.3:a:cryptopp:crypto++:8.0.0
-
cpe:2.3:a:cryptopp:crypto++:8.1.0
-
cpe:2.3:a:cryptopp:crypto++:8.2.0
-
cpe:2.3:a:cryptopp:crypto++:8.3.0
-
cpe:2.3:a:cryptopp:crypto++:8.4.0
-
cpe:2.3:a:cryptopp:crypto++:8.5.0
-
cpe:2.3:a:cryptopp:crypto++:8.6.0
-
cpe:2.3:a:cryptopp:crypto++:8.7.0
-
cpe:2.3:a:cryptopp:crypto++:8.8.0
-
cpe:2.3:a:cryptopp:crypto++:8.9.0