CVE-2016-7420 — Sensitive Information Exposure in Crypto
Severity
5.9MEDIUMNVD
EPSS
0.4%
top 40.50%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 16
Latest updateMay 17
Description
Crypto++ (aka cryptopp) through 5.6.4 does not document the requirement for a compile-time NDEBUG definition disabling the many assert calls that are unintended in production use, which might allow context-dependent attackers to obtain sensitive information by leveraging access to process memory after an assertion failure, as demonstrated by reading a core dump.
CVSS vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 2.2 | Impact: 3.6
Affected Packages2 packages
Patches
🔴Vulnerability Details
2📋Vendor Advisories
3💬Community
3Bugzilla▶
CVE-2016-7420 cryptopp: Library documentation lacks treatment of -DNDEBUG and Static Initialization [epel-all]↗2016-09-16
Bugzilla▶
CVE-2016-7420 cryptopp: Library documentation lacks treatment of -DNDEBUG and Static Initialization↗2016-09-16
Bugzilla▶
CVE-2016-7420 cryptopp: Library documentation lacks treatment of -DNDEBUG and Static Initialization [fedora-all]↗2016-09-16