Vulnerabilities > CVE-2016-7544 - Resource Management Errors vulnerability in Cryptopp Crypto++ 5.6.4
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
NONE Integrity impact
NONE Availability impact
HIGH Summary
Crypto++ 5.6.4 incorrectly uses Microsoft's stack-based _malloca and _freea functions. The library will request a block of memory to align a table in memory. If the table is later reallocated, then the wrong pointer could be freed.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 | |
OS | 1 |
Common Weakness Enumeration (CWE)
References
- http://www.openwall.com/lists/oss-security/2016/09/23/5
- http://www.openwall.com/lists/oss-security/2016/09/23/5
- http://www.openwall.com/lists/oss-security/2016/09/23/9
- http://www.openwall.com/lists/oss-security/2016/09/23/9
- http://www.securityfocus.com/bid/93164
- http://www.securityfocus.com/bid/93164
- https://github.com/weidai11/cryptopp/issues/302
- https://github.com/weidai11/cryptopp/issues/302
- https://www.cryptopp.com/release565.html
- https://www.cryptopp.com/release565.html