CVE-2016-7420: Cryptopp Crypto++
Medium severity, CVSS 5.9. EPSS: 2% chance of exploitation in the next 30 days.
Crypto++ (aka cryptopp) through 5.6.4 does not document the requirement for a compile-time NDEBUG definition disabling the many assert calls that are unintended in production use, which might allow context-dependent attackers to obtain sensitive information by leveraging access to process memory after an assertion failure, as demonstrated by reading a core dump.
Affected products
- Cryptopp Crypto++: up to and including 5.6.4
Published 2016-09-16. Last modified 2026-06-17.