CVE-2015-7827Sensitive Information Exposure in Project Botan

Severity
7.5HIGHNVD
EPSS
0.4%
top 37.10%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 13
Latest updateMay 17

Description

Botan before 1.10.13 and 1.11.x before 1.11.22 make it easier for remote attackers to conduct million-message attacks by measuring time differences, related to decoding of PKCS#1 padding.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages1 packages

NVDbotan_project/botan1.10.13+22

Also affects: Debian Linux 8.0, Fedora 24

🔴Vulnerability Details

2
GHSA
GHSA-hqg9-gjhg-w3qg: Botan before 12022-05-17
OSV
CVE-2015-7827: Botan before 12016-05-13

💬Community

2
Bugzilla
CVE-2016-2849 CVE-2016-2850 botan: two issues fixed in 1.11.292016-04-27
Bugzilla
CVE-2015-7827 botan: PKCS #1 decoding not in constant time2016-02-25