PT-2017-13660 · Botan+2 · Botan+2
Published
2017-09-26
·
Updated
2024-06-15
·
CVE-2017-14737
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Botan versions prior to 1.10.17
Botan versions 1.11.x
Botan versions 2.x prior to 2.3.0
Description
A cryptographic cache-based side channel in the RSA implementation allows a local attacker to recover information about RSA secret keys. This occurs because an array is indexed with bits derived from a
secret key. The issue is demonstrated by CacheD.Recommendations
For Botan versions prior to 1.10.17, update to version 1.10.17 or later.
For Botan versions 1.11.x, update to version 2.3.0 or later.
For Botan versions 2.x prior to 2.3.0, update to version 2.3.0 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Botan
Suse