Vulnerabilities
Vulnerable Software
Botan Project:  >> Botan  >> 1.11.34  Security Vulnerabilities
An issue was discovered in Botan 1.11.32 through 2.x before 2.6.0. An off-by-one error when processing malformed TLS-CBC ciphertext could cause the receiving side to include in the HMAC computation exactly 64K bytes of data following the record buffer, aka an over-read. The MAC comparison will subsequently fail and the connection will be closed. This could be used for denial of service. No information leak occurs.
CVSS Score
7.5
EPSS Score
0.004
Published
2018-04-12
A cryptographic cache-based side channel in the RSA implementation in Botan before 1.10.17, and 1.11.x and 2.x before 2.3.0, allows a local attacker to recover information about RSA secret keys, as demonstrated by CacheD. This occurs because an array is indexed with bits derived from a secret key.
CVSS Score
5.5
EPSS Score
0.001
Published
2017-09-26


Contact Us

Shodan ® - All rights reserved