PT-2017-13660 · Botan+2 · Botan+2

Publicado

2017-09-26

·

Atualizado

2024-06-15

·

CVE-2017-14737

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Botan versions prior to 1.10.17 Botan versions 1.11.x Botan versions 2.x prior to 2.3.0
Description A cryptographic cache-based side channel in the RSA implementation allows a local attacker to recover information about RSA secret keys. This occurs because an array is indexed with bits derived from a secret key. The issue is demonstrated by CacheD.
Recommendations For Botan versions prior to 1.10.17, update to version 1.10.17 or later. For Botan versions 1.11.x, update to version 2.3.0 or later. For Botan versions 2.x prior to 2.3.0, update to version 2.3.0 or later.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

ALT-PU-2018-1589
CVE-2017-14737
DLA-1125-1
DLA-2812-1
MGASA-2017-0422
OPENSUSE-SU-2024:10594-1
SUSE-SU-2017:2855-1
SUSE-SU-2017_2855-1

Produtos afetados

Alt Linux
Botan
Suse