PT-2023-10644 · Botan · Botan

Solar Designer

·

Publicado

2023-11-03

·

Atualizado

2023-11-13

·

CVE-2017-7252

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Botan versions prior to 2.1.0
Description The issue concerns bcrypt password hashing in Botan, where passwords with a length between 57 and 72 characters are not handled correctly. This incorrect handling makes it easier for attackers to determine the cleartext password.
Recommendations For versions prior to 2.1.0, update to version 2.1.0 or later to resolve the issue. As a temporary workaround, consider avoiding the use of passwords with lengths between 57 and 72 characters until the update is applied.

Correção

Cleartext Transmission of Sensitive Information

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-7252

Produtos afetados

Botan