CVE-2017-9434: Medium severity Cryptopp Crypto\+\+ vulnerability
Published Jun 5, 2017
·Updated
Crypto++ (aka cryptopp) through 5.6.5 contains an out-of-bounds read vulnerability in zinflate.cpp in the Inflator filter.
Affected Software
1 affected component
Cryptopp Crypto\+\+<=5.6.4
Event History
Jun 5, 2017
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-9434?
CVE-2017-9434 has been classified as a high severity vulnerability due to its potential to allow an attacker to exploit the out-of-bounds read.
2
How do I fix CVE-2017-9434?
To mitigate CVE-2017-9434, upgrade your Crypto++ library to version 5.6.5 or later.
3
What type of vulnerability is CVE-2017-9434?
CVE-2017-9434 is an out-of-bounds read vulnerability found in the Inflator filter of the Crypto++ library.
4
Which versions of Crypto++ are affected by CVE-2017-9434?
Crypto++ versions up to and including 5.6.4 are affected by CVE-2017-9434.
5
Can CVE-2017-9434 affect software dependent on Crypto++?
Yes, any software that uses the vulnerable versions of Crypto++ could be at risk due to CVE-2017-9434.