Vulnerabilities
Vulnerable Software
Botan Project:  >> Botan  >> 1.11.24  Security Vulnerabilities
Botan before 1.10.13 and 1.11.x before 1.11.29 do not use a constant-time algorithm to perform a modular inverse on the signature nonce k, which might allow remote attackers to obtain ECDSA secret keys via a timing side-channel attack.
CVSS Score
7.5
EPSS Score
0.006
Published
2016-05-13
Heap-based buffer overflow in the P-521 reduction function in Botan 1.11.x before 1.11.27 allows remote attackers to cause a denial of service (memory overwrite and crash) or execute arbitrary code via unspecified vectors.
CVSS Score
9.8
EPSS Score
0.024
Published
2016-05-13
Integer overflow in the PointGFp constructor in Botan before 1.10.11 and 1.11.x before 1.11.27 allows remote attackers to overwrite memory and possibly execute arbitrary code via a crafted ECC point, which triggers a heap-based buffer overflow.
CVSS Score
9.8
EPSS Score
0.057
Published
2016-05-13
The ressol function in Botan before 1.10.11 and 1.11.x before 1.11.27 allows remote attackers to cause a denial of service (infinite loop) via unspecified input to the OS2ECP function, related to a composite modulus.
CVSS Score
7.5
EPSS Score
0.017
Published
2016-05-13


Contact Us

Shodan ® - All rights reserved