High severity7.5NVD Advisory· Published Dec 18, 2023· Updated Jun 17, 2026
CVE-2023-50980
CVE-2023-50980
Description
gf2n.cpp in Crypto++ (aka cryptopp) through 8.9.0 allows attackers to cause a denial of service (application crash) via DER public-key data for an F(2^m) curve, if the degree of each term in the polynomial is not strictly decreasing.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7- Crypto++/Crypto++description
- Range: <=8.9.0
- osv-coords5 versionspkg:rpm/opensuse/libcryptopp&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/libcryptopp&distro=openSUSE%20Leap%2015.5pkg:rpm/opensuse/libcryptopp&distro=openSUSE%20Tumbleweedpkg:rpm/suse/libcryptopp&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP5pkg:rpm/suse/libcryptopp&distro=SUSE%20Linux%20Enterprise%20Real%20Time%2015%20SP4
< 5.6.5-150000.1.9.1+ 4 more
- (no CPE)range: < 5.6.5-150000.1.9.1
- (no CPE)range: < 8.6.0-150400.3.3.1
- (no CPE)range: < 8.9.0-1.1
- (no CPE)range: < 8.6.0-150400.3.3.1
- (no CPE)range: < 8.6.0-150400.3.3.1
Patches
Vulnerability mechanics
References
1- github.com/weidai11/cryptopp/issues/1248nvdExploitIssue Tracking
News mentions
0No linked articles in our index yet.