Vulnerabilities
Vulnerable Software
Botan Project:  >> Botan  >> 1.11.32  Security Vulnerabilities
In Botan 1.8.0 through 1.11.33, when decoding BER data an integer overflow could occur, which would cause an incorrect length field to be computed. Some API callers may use the returned (incorrect and attacker controlled) length field in a way which later causes memory corruption or other failure.
CVSS Score
9.8
EPSS Score
0.003
Published
2017-01-30
In Botan 1.11.29 through 1.11.32, RSA decryption with certain padding options had a detectable timing channel which could given sufficient queries be used to recover plaintext, aka an "OAEP side channel" attack.
CVSS Score
6.2
EPSS Score
0.001
Published
2016-10-28


Contact Us

Shodan ® - All rights reserved