[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249461

 
 

909

 
 

195508

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

CVE-2016-7420 -- libcrypto++

ID: oval:org.secpod.oval:def:2000351Date: (C)2019-06-02   (M)2023-10-05
Class: VULNERABILITYFamily: unix




Crypto++ through 5.6.4 does not document the requirement for a compile-time NDEBUG definition disabling the many assert calls that are unintended in production use, which might allow context-dependent attackers to obtain sensitive information by leveraging access to process memory after an assertion failure, as demonstrated by reading a core dump.

Platform:
Debian 8.x
Debian 9.x
Product:
libcrypto++-dev
Reference:
CVE-2016-7420
CVE    1
CVE-2016-7420
CPE    3
cpe:/o:debian:debian_linux:8.x
cpe:/o:debian:debian_linux:9.x
cpe:/a:libcrypto++:libcrypto++-dev

© SecPod Technologies