Medium severity5.9NVD Advisory· Published Sep 6, 2021· Updated Jun 17, 2026
CVE-2021-40530
CVE-2021-40530
Description
The ElGamal implementation in Crypto++ through 8.5 allows plaintext recovery because, during interaction between two cryptographic libraries, a certain dangerous combination of the prime defined by the receiver's public key, the generator defined by the receiver's public key, and the sender's ephemeral exponents can lead to a cross-configuration attack against OpenPGP.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Crypto++/Crypto++description
- Range: <=8.5
Patches
Vulnerability mechanics
References
6- ibm.github.io/system-security-research-updates/2021/09/06/insecurity-elgamal-pt2nvdExploitThird Party Advisory
- eprint.iacr.org/2021/923nvdTechnical DescriptionThird Party Advisory
- ibm.github.io/system-security-research-updates/2021/07/20/insecurity-elgamal-pt1nvdThird Party Advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/57OJA2K5AHX5HAU2QBDRWLGIIUX7GASC/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HGVBZ2TTRKCTYAZTRHTF6OBD4W37F5MT/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VJYOZGWI7TD27SEXILSM6VUTPPEICDL7/nvd
News mentions
0No linked articles in our index yet.