VYPR
Medium severity5.9NVD Advisory· Published Sep 6, 2021· Updated Jun 17, 2026

CVE-2021-40530

CVE-2021-40530

Description

The ElGamal implementation in Crypto++ through 8.5 allows plaintext recovery because, during interaction between two cryptographic libraries, a certain dangerous combination of the prime defined by the receiver's public key, the generator defined by the receiver's public key, and the sender's ephemeral exponents can lead to a cross-configuration attack against OpenPGP.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

7
  • cpe:2.3:a:cryptopp:crypto\+\+:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:cryptopp:crypto\+\+:*:*:*:*:*:*:*:*range: <=8.5
    • (no CPE)range: <=8.5
  • cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*
    • cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*
    • cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
  • Crypto++/Crypto++description

Patches

Vulnerability mechanics

References

6

News mentions

0

No linked articles in our index yet.