CVE-2015-7827
published 2016-05-13CVE-2015-7827: Botan before 1.10.13 and 1.11.x before 1.11.22 make it easier for remote attackers to conduct million-message attacks by measuring time differences, related to…
PriorityP342high7.5CVSS 3.0
AVNACLPRNUINSUCHINAN
EPSS
2.44%
82.5th percentile
Botan before 1.10.13 and 1.11.x before 1.11.22 make it easier for remote attackers to conduct million-message attacks by measuring time differences, related to decoding of PKCS#1 padding.
Affected
25 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| botan_project | botan | <= 1.10.13 | — |
| botan_project | botan | — | — |
| botan_project | botan | — | — |
| botan_project | botan | — | — |
| botan_project | botan | — | — |
| botan_project | botan | — | — |
| botan_project | botan | — | — |
| botan_project | botan | — | — |
| botan_project | botan | — | — |
| botan_project | botan | — | — |
| botan_project | botan | — | — |
| botan_project | botan | — | — |
| botan_project | botan | — | — |
| botan_project | botan | — | — |
| botan_project | botan | — | — |
| botan_project | botan | — | — |
| botan_project | botan | — | — |
| botan_project | botan | — | — |
| botan_project | botan | — | — |
| botan_project | botan | — | — |
| botan_project | botan | — | — |
| botan_project | botan | — | — |
| botan_project | botan | — | — |
| debian | debian_linux | — | — |
| fedoraproject | fedora | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hqg9-gjhg-w3qg: Botan before 1
ghsa_unreviewed·2022-05-17
CVE-2015-7827 [HIGH] CWE-200 GHSA-hqg9-gjhg-w3qg: Botan before 1
Botan before 1.10.13 and 1.11.x before 1.11.22 make it easier for remote attackers to conduct million-message attacks by measuring time differences, related to decoding of PKCS#1 padding.
OSV
CVE-2015-7827: Botan before 1
osv·2016-05-13·CVSS 7.5
CVE-2015-7827 [HIGH] CVE-2015-7827: Botan before 1
Botan before 1.10.13 and 1.11.x before 1.11.22 make it easier for remote attackers to conduct million-message attacks by measuring time differences, related to decoding of PKCS#1 padding.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-2849 CVE-2016-2850 botan: two issues fixed in 1.11.29
bugzilla·2016-04-27·CVSS 7.5
CVE-2016-2849 [HIGH] CVE-2016-2849 CVE-2016-2850 botan: two issues fixed in 1.11.29
CVE-2016-2849 CVE-2016-2850 botan: two issues fixed in 1.11.29
The following issues were fixed in the 1.11.29 release of botan:
(CVE-2016-2849): ECDSA side channel
ECDSA (and DSA) signature algorithms perform a modular inverse on the signature nonce k. The modular inverse algorithm used had input dependent loops, and it is possible a side channel attack could recover sufficient information about the nonce to eventually recover the ECDSA secret key. Found by Sean Devlin.
Introduced in 1.7.15, fixed in 1.11.29
2016-03-17 (CVE-2016-2850): Failure to enforce TLS policy
TLS v1.2 allows negotiating which signature algorithms and hash functions each side is willing to accept. However received signatures were not actually checked against the specified policy. This had the effect of allowing
Bugzilla
CVE-2015-7827 botan: PKCS #1 decoding not in constant time
bugzilla·2016-02-25·CVSS 7.5
CVE-2015-7827 [HIGH] CVE-2015-7827 botan: PKCS #1 decoding not in constant time
CVE-2015-7827 botan: PKCS #1 decoding not in constant time
During RSA decryption, length of decoding of PKCS #1 v1.5 padding took was input dependent. If these differences could be measured by an attacker, it could be used to mount a Bleichenbacher million-message attack. PKCS #1 v1.5 decoding has been rewritten to use a sequence of operations which do not contain any input-dependent indexes or jumps. Notations for checking constant time blocks with ctgrind (https://github.com/agl/ctgrind) were added to PKCS #1 decoding among other areas.
External references:
http://botan.randombit.net/security.html
Discussion:
botan-1.10.13-1.fc24 has been pushed to the Fedora 24 stable repository. If problems still persist, please make note of it in this bug report.
---
botan-1.10.13-1.fc23 has be
http://botan.randombit.net/security.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-May/183669.htmlhttp://marc.info/?l=botan-devel&m=146185420505943&w=2http://www.debian.org/security/2016/dsa-3565http://botan.randombit.net/security.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-May/183669.htmlhttp://marc.info/?l=botan-devel&m=146185420505943&w=2http://www.debian.org/security/2016/dsa-3565
2016-05-13
Published