Vulnerabilities
Vulnerable Software
Botan Project:  >> Botan  >> 1.11.29  Security Vulnerabilities
The X509_Certificate::allowed_usage function in botan 1.11.x before 1.11.31 might allow attackers to have unspecified impact by leveraging a call with more than one Key_Usage set in the enum value.
CVSS Score
7.5
EPSS Score
0.002
Published
2017-04-10
In Botan 1.8.0 through 1.11.33, when decoding BER data an integer overflow could occur, which would cause an incorrect length field to be computed. Some API callers may use the returned (incorrect and attacker controlled) length field in a way which later causes memory corruption or other failure.
CVSS Score
9.8
EPSS Score
0.003
Published
2017-01-30
In Botan 1.11.29 through 1.11.32, RSA decryption with certain padding options had a detectable timing channel which could given sufficient queries be used to recover plaintext, aka an "OAEP side channel" attack.
CVSS Score
6.2
EPSS Score
0.001
Published
2016-10-28


Contact Us

Shodan ® - All rights reserved