PT-2019-10012 · Botan+1 · Botan+1

Ján Jančár

·

Published

2019-03-08

·

Updated

2024-06-15

·

CVE-2018-20187

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Botan versions prior to 2.9.0
Description: A side-channel issue was discovered that affects the ECC key generation process. An attacker capable of precisely measuring the time taken for key generation may be able to derive information about the high bits of the secret key. This is due to the use of an unblinded Montgomery ladder in the function to derive the public point from the secret scalar, whose loop iteration count depends on the bitlength of the secret. This issue only affects key generation and does not impact ECDSA signatures or ECDH key agreement.
Recommendations: For versions prior to 2.9.0, update to version 2.9.0 or later to resolve the issue. As a temporary workaround, consider implementing timing-based mitigations to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-1441
CVE-2018-20187
OPENSUSE-SU-2024:10594-1

Affected Products

Alt Linux
Botan