CVE-2016-7420
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Crypto++ (aka cryptopp) through 5.6.4 does not document the requirement for a compile-time NDEBUG definition disabling the many assert calls that are unintended in production use, which might allow context-dependent attackers to obtain sensitive information by leveraging access to process memory after an assertion failure, as demonstrated by reading a core dump.
Crypto++ (también conocido como cryptopp) hasta la versión 5.6.4 no documenta el requisito para una definición NDEBUG de tiempo de compilación deshabilitando las múltiples llamadas assert que son no intencionadas en uso de producción, lo que podría permitir a atacantes dependientes del contexto obtener información sensible aprovechando acceso a la memoria de procesamiento después de un fallo de aserción, según lo demostrado mediante la lectura de un volcado de memoria.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2016-09-09 CVE Reserved
- 2016-09-16 CVE Published
- 2023-09-29 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (7)
URL | Tag | Source |
---|---|---|
http://www.openwall.com/lists/oss-security/2016/09/15/12 | Mailing List | |
http://www.openwall.com/lists/oss-security/2016/09/16/1 | Mailing List | |
http://www.openwall.com/lists/oss-security/2023/09/28/2 | Mailing List | |
http://www.openwall.com/lists/oss-security/2023/09/28/4 | Mailing List | |
http://www.securityfocus.com/bid/92988 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/weidai11/cryptopp/commit/553049ba297d89d9e8fbf2204acb40a8a53f5cd6 | 2023-09-28 | |
https://github.com/weidai11/cryptopp/issues/277 | 2023-09-28 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cryptopp Search vendor "Cryptopp" | Crypto\+\+ Search vendor "Cryptopp" for product "Crypto\+\+" | <= 5.6.4 Search vendor "Cryptopp" for product "Crypto\+\+" and version " <= 5.6.4" | - |
Affected
|