PT-2017-15546 · Randombit+1 · Botan+1

Aleksandar Nikolic

·

Publicado

2017-05-09

·

Atualizado

2024-06-15

·

CVE-2017-2801

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Randombit Botan cryptographic library version 2.0.1
Description A programming error in the Randombit Botan cryptographic library could lead to certificate verification issues. This issue arises from the way the library implements x500 string comparisons, potentially allowing abuse. To trigger this issue, a specially crafted X509 certificate would need to be delivered to the client or server application.
Recommendations For Randombit Botan cryptographic library version 2.0.1, consider updating to a newer version that addresses this issue, as the current version may lead to certificate verification problems. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Out of bounds Read

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-2801
DLA-915-1
DSA-3939-1
MGASA-2017-0321
MGASA-2017-0327
OPENSUSE-SU-2024:10594-1
SUSE-SU-2017:1222-1

Produtos afetados

Botan
Suse