CVE-2016-3995
published 2017-02-13CVE-2016-3995: The timing attack protection in Rijndael::Enc::ProcessAndXorBlock and Rijndael::Dec::ProcessAndXorBlock in Crypto++ (aka cryptopp) before 5.6.4 may be…
PriorityP336high7.5CVSS 3.0
AVNACLPRNUINSUCHINAN
EPSS
1.86%
77.1th percentile
The timing attack protection in Rijndael::Enc::ProcessAndXorBlock and Rijndael::Dec::ProcessAndXorBlock in Crypto++ (aka cryptopp) before 5.6.4 may be optimized out by the compiler, which allows attackers to conduct timing attacks.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cryptopp | crypto | <= 5.6.3 | — |
| debian | libcrypto | < libcrypto++ 5.6.3-6 (bookworm) | libcrypto++ 5.6.3-6 (bookworm) |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv7.5HIGH
vendor_redhat8.8HIGH
vendor_debian7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-rfvf-996j-mmvf: The timing attack protection in Rijndael::Enc::ProcessAndXorBlock and Rijndael::Dec::ProcessAndXorBlock in Crypto++ (aka cryptopp) before 5
ghsa_unreviewed·2022-05-17
CVE-2016-3995 [HIGH] CWE-200 GHSA-rfvf-996j-mmvf: The timing attack protection in Rijndael::Enc::ProcessAndXorBlock and Rijndael::Dec::ProcessAndXorBlock in Crypto++ (aka cryptopp) before 5
The timing attack protection in Rijndael::Enc::ProcessAndXorBlock and Rijndael::Dec::ProcessAndXorBlock in Crypto++ (aka cryptopp) before 5.6.4 may be optimized out by the compiler, which allows attackers to conduct timing attacks.
OSV
CVE-2016-3995: The timing attack protection in Rijndael::Enc::ProcessAndXorBlock and Rijndael::Dec::ProcessAndXorBlock in Crypto++ (aka cryptopp) before 5
osv·2017-02-13·CVSS 7.5
CVE-2016-3995 [HIGH] CVE-2016-3995: The timing attack protection in Rijndael::Enc::ProcessAndXorBlock and Rijndael::Dec::ProcessAndXorBlock in Crypto++ (aka cryptopp) before 5
The timing attack protection in Rijndael::Enc::ProcessAndXorBlock and Rijndael::Dec::ProcessAndXorBlock in Crypto++ (aka cryptopp) before 5.6.4 may be optimized out by the compiler, which allows attackers to conduct timing attacks.
Red Hat
samba: NDR Parsing ndr_pull_dnsp_name Heap-based Buffer Overflow Remote Code Execution Vulnerability (ZDI-CAN-3995)
vendor_redhat·2016-12-19·CVSS 8.8
CVE-2016-2123 [HIGH] CWE-122 samba: NDR Parsing ndr_pull_dnsp_name Heap-based Buffer Overflow Remote Code Execution Vulnerability (ZDI-CAN-3995)
samba: NDR Parsing ndr_pull_dnsp_name Heap-based Buffer Overflow Remote Code Execution Vulnerability (ZDI-CAN-3995)
A flaw was found in samba versions 4.0.0 to 4.5.2. The Samba routine ndr_pull_dnsp_name contains an integer wrap problem, leading to an attacker-controlled memory overwrite. ndr_pull_dnsp_name parses data from the Samba Active Directory ldb database. Any user who can write to the dnsRecord attribute over LDAP can trigger this memory corruption. By default, all authenticated LDAP users can write to the dnsRecord attribute on new DNS objects. This makes the defect a remote privilege escalation.
Statement: Red Hat Enterprise Linux 5, 6 and 7 are not affected by this flaw because we do not ship Samba with the AD DNS Server, which is the vulnerable component.
Package: samba (Re
Debian
CVE-2016-3995: libcrypto++ - The timing attack protection in Rijndael::Enc::ProcessAndXorBlock and Rijndael::...
vendor_debian·2016·CVSS 7.5
CVE-2016-3995 [HIGH] CVE-2016-3995: libcrypto++ - The timing attack protection in Rijndael::Enc::ProcessAndXorBlock and Rijndael::...
The timing attack protection in Rijndael::Enc::ProcessAndXorBlock and Rijndael::Dec::ProcessAndXorBlock in Crypto++ (aka cryptopp) before 5.6.4 may be optimized out by the compiler, which allows attackers to conduct timing attacks.
Scope: local
bookworm: resolved (fixed in 5.6.3-6)
bullseye: resolved (fixed in 5.6.3-6)
forky: resolved (fixed in 5.6.3-6)
sid: resolved (fixed in 5.6.3-6)
trixie: resolved (fixed in 5.6.3-6)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-2123 samba: NDR Parsing ndr_pull_dnsp_name Heap-based Buffer Overflow Remote Code Execution Vulnerability (ZDI-CAN-3995)
bugzilla·2016-11-08·CVSS 8.8
CVE-2016-2123 [HIGH] CVE-2016-2123 samba: NDR Parsing ndr_pull_dnsp_name Heap-based Buffer Overflow Remote Code Execution Vulnerability (ZDI-CAN-3995)
CVE-2016-2123 samba: NDR Parsing ndr_pull_dnsp_name Heap-based Buffer Overflow Remote Code Execution Vulnerability (ZDI-CAN-3995)
As per upstream:
The Samba routine ndr_pull_dnsp_name contains an integer wrap problem, leading to an attacker-controlled memory overwrite. ndr_pull_dnsp_name parses data from the Samba Active Directory ldb database. Any user who can write to the dnsRecord attribute over LDAP can trigger this memory corruption.
By default, all authenticated LDAP users can write to the dnsRecord attribute on new DNS objects. This makes the defect a remote privilege escalation.
Discussion:
Statement:
Red Hat Enterprise Linux 5, 6 and 7 are not affected by this flaw because we do not ship Samba with the AD DNS Server, which is the vulnerable component.
---
External Referenc
Bugzilla
CVE-2016-3995 cryptopp: bogus protection from timing attacks [fedora-all]
bugzilla·2016-04-11·CVSS 7.5
CVE-2016-3995 [HIGH] CVE-2016-3995 cryptopp: bogus protection from timing attacks [fedora-all]
CVE-2016-3995 cryptopp: bogus protection from timing attacks [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedo
Bugzilla
CVE-2016-3995 cryptopp: bogus protection from timing attacks [epel-7]
bugzilla·2016-04-11·CVSS 7.5
CVE-2016-3995 [HIGH] CVE-2016-3995 cryptopp: bogus protection from timing attacks [epel-7]
CVE-2016-3995 cryptopp: bogus protection from timing attacks [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
[bug automatically created by: add-tracking-bugs]
Discuss
Bugzilla
CVE-2016-3995 cryptopp: bogus protection from timing attacks [epel-6]
bugzilla·2016-04-11·CVSS 7.5
CVE-2016-3995 [HIGH] CVE-2016-3995 cryptopp: bogus protection from timing attacks [epel-6]
CVE-2016-3995 cryptopp: bogus protection from timing attacks [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
[bug automatically created by: add-tracking-bugs]
Discuss
Bugzilla
CVE-2016-3995 cryptopp: bogus protection from timing attacks
bugzilla·2016-04-11·CVSS 7.5
CVE-2016-3995 [HIGH] CVE-2016-3995 cryptopp: bogus protection from timing attacks
CVE-2016-3995 cryptopp: bogus protection from timing attacks
A vulnerability was found in cryptopp library. A counter measure against timing attack was incorrectly implemented.
External references:
https://github.com/weidai11/cryptopp/issues/146
References and CVE assignment:
http://seclists.org/oss-sec/2016/q2/50
Discussion:
Created cryptopp tracking bugs for this issue:
Affects: fedora-all [bug 1325949]
Affects: epel-6 [bug 1325950]
Affects: epel-7 [bug 1325951]
---
cryptopp-5.6.3-3.fc24 has been pushed to the Fedora 24 stable repository. If problems still persist, please make note of it in this bug report.
---
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the
2017-02-13
Published