PT-2017-15546 · Randombit+1 · Botan+1

Aleksandar Nikolic

·

Published

2017-05-09

·

Updated

2024-06-15

·

CVE-2017-2801

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Randombit Botan cryptographic library version 2.0.1
Description A programming error in the Randombit Botan cryptographic library could lead to certificate verification issues. This issue arises from the way the library implements x500 string comparisons, potentially allowing abuse. To trigger this issue, a specially crafted X509 certificate would need to be delivered to the client or server application.
Recommendations For Randombit Botan cryptographic library version 2.0.1, consider updating to a newer version that addresses this issue, as the current version may lead to certificate verification problems. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-2801
DLA-915-1
DSA-3939-1
MGASA-2017-0321
MGASA-2017-0327
OPENSUSE-SU-2024:10594-1
SUSE-SU-2017:1222-1

Affected Products

Botan
Suse