PT-2017-13660 · Botan+2 · Botan+2
Publicado
2017-09-26
·
Atualizado
2024-06-15
·
CVE-2017-14737
CVSS v3.1
5.5
Média
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Botan versions prior to 1.10.17
Botan versions 1.11.x
Botan versions 2.x prior to 2.3.0
Description
A cryptographic cache-based side channel in the RSA implementation allows a local attacker to recover information about RSA secret keys. This occurs because an array is indexed with bits derived from a
secret key. The issue is demonstrated by CacheD.Recommendations
For Botan versions prior to 1.10.17, update to version 1.10.17 or later.
For Botan versions 1.11.x, update to version 2.3.0 or later.
For Botan versions 2.x prior to 2.3.0, update to version 2.3.0 or later.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Alt Linux
Botan
Suse