Vulnerabilities
Vulnerable Software
Botan Project:  >> Botan  >> 1.10.16  Security Vulnerabilities
botan before 1.11.22 improperly validates certificate paths, which allows remote attackers to cause a denial of service (infinite loop and memory consumption) via a certificate with a loop in the certificate chain.
CVSS Score
7.5
EPSS Score
0.003
Published
2017-04-10
botan 1.11.x before 1.11.22 improperly handles wildcard matching against hostnames, which might allow remote attackers to have unspecified impact via a valid X.509 certificate, as demonstrated by accepting *.example.com as a match for bar.foo.example.com.
CVSS Score
9.8
EPSS Score
0.004
Published
2017-04-10
The Curve25519 code in botan before 1.11.31, on systems without a native 128-bit integer type, might allow attackers to have unspecified impact via vectors related to undefined behavior, as demonstrated on 32-bit ARM systems compiled by Clang.
CVSS Score
9.8
EPSS Score
0.004
Published
2017-04-10


Contact Us

Shodan ® - All rights reserved