Information Exposure Affecting ipp-crypto package, versions [,2021.7.0)


Severity

Recommended
0.0
low
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PYTHON-IPPCRYPTO-5518127
  • published11 May 2023
  • disclosed11 May 2023
  • creditUnknown

Introduced: 11 May 2023

CVE NOT AVAILABLE CWE-200  (opens in a new tab)

How to fix?

Upgrade ipp-crypto to version 2021.7.0 or higher.

Overview

ipp-crypto is a library for Intel Integrated Performance Primitives Cryptography

Affected versions of this package are vulnerable to Information Exposure via Frequency Throttling Side-Channel attacks for ECB, CMAC and GCM AES modes. An attacker with low level access who can execute repeated cryptographic operations on the affected system using the same key (i.e. without exceeding the configured time or volume threshhold for refreshing the secret key) can extract potentially sensitive information from an unauthorized workload. A number of prerequisite conditions must be met for an attack to be practical. See Frequency Throttling Side Channel Software Guidance for Cryptography Implementations for more information.

CVSS Base Scores

version 3.1