VDB
CVE-2016-9939
CVE-2016-9939
PUBLISHED
CVSS 7.5 HIGH
Crypto++ (aka cryptopp and libcrypto++) 5.6.4 contained a bug in its ASN.1 BER decoding routine. The library will allocate a memory block based on the length field of the ASN.1 object. If there is not enough content octets in the ASN.1 object, then the function will fail and the memory block will be zeroed even if its unused. There is a noticeable delay during the wipe for a large allocation.
EPSS 4.20% · 90.6th percentile
Risk Scores
CVSS 3.0
7.5
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
4.20%
90.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:14.04:LTS | libcrypto++ | 0, 5.6.1-6, 5.6.1-6+deb8u1build0.14.04.1 |
| Ubuntu:16.04:LTS | libcrypto++ | 0, 5.6.1-8, 5.6.1-9 |
Timeline
- Jan 30, 2017 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 13, 2022 EPSS Score
- Sep 5, 2022 EPSS Score
- Dec 20, 2022 EPSS Score
- Feb 11, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- May 28, 2023 EPSS Score
- Jul 20, 2023 EPSS Score
- Sep 11, 2023 EPSS Score
- Dec 26, 2023 EPSS Score
References
- https://ubuntu.com/security/CVE-2016-9939 third-party-advisory
- https://github.com/weidai11/cryptopp/issues/346 third-party-advisory
- http://www.openwall.com/lists/oss-security/2016/12/12/6 third-party-advisory
- https://www.cve.org/CVERecord?id=CVE-2016-9939 third-party-advisory