PT-2017-13660 · Botan+2 · Botan+2

Published

2017-09-26

·

Updated

2024-06-15

·

CVE-2017-14737

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Botan versions prior to 1.10.17 Botan versions 1.11.x Botan versions 2.x prior to 2.3.0
Description A cryptographic cache-based side channel in the RSA implementation allows a local attacker to recover information about RSA secret keys. This occurs because an array is indexed with bits derived from a secret key. The issue is demonstrated by CacheD.
Recommendations For Botan versions prior to 1.10.17, update to version 1.10.17 or later. For Botan versions 1.11.x, update to version 2.3.0 or later. For Botan versions 2.x prior to 2.3.0, update to version 2.3.0 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

ALT-PU-2018-1589
CVE-2017-14737
DLA-1125-1
DLA-2812-1
MGASA-2017-0422
OPENSUSE-SU-2024:10594-1
SUSE-SU-2017:2855-1
SUSE-SU-2017_2855-1

Affected Products

Alt Linux
Botan
Suse