CVE-2016-9132
published 2017-01-30CVE-2016-9132: In Botan 1.8.0 through 1.11.33, when decoding BER data an integer overflow could occur, which would cause an incorrect length field to be computed. Some API…
PriorityP341critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
1.98%
78.3th percentile
In Botan 1.8.0 through 1.11.33, when decoding BER data an integer overflow could occur, which would cause an incorrect length field to be computed. Some API callers may use the returned (incorrect and attacker controlled) length field in a way which later causes memory corruption or other failure.
Affected
84 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| botan_project | botan | — | — |
| botan_project | botan | — | — |
| botan_project | botan | — | — |
| botan_project | botan | — | — |
| botan_project | botan | — | — |
| botan_project | botan | — | — |
| botan_project | botan | — | — |
| botan_project | botan | — | — |
| botan_project | botan | — | — |
| botan_project | botan | — | — |
| botan_project | botan | — | — |
| botan_project | botan | — | — |
| botan_project | botan | — | — |
| botan_project | botan | — | — |
| botan_project | botan | — | — |
| botan_project | botan | — | — |
| botan_project | botan | — | — |
| botan_project | botan | — | — |
| botan_project | botan | — | — |
| botan_project | botan | — | — |
| botan_project | botan | — | — |
| botan_project | botan | — | — |
| botan_project | botan | — | — |
| botan_project | botan | — | — |
| botan_project | botan | — | — |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-674g-g96j-pr63: In Botan 1
ghsa_unreviewed·2022-05-17
CVE-2016-9132 [CRITICAL] CWE-190 GHSA-674g-g96j-pr63: In Botan 1
In Botan 1.8.0 through 1.11.33, when decoding BER data an integer overflow could occur, which would cause an incorrect length field to be computed. Some API callers may use the returned (incorrect and attacker controlled) length field in a way which later causes memory corruption or other failure.
OSV
CVE-2016-9132: In Botan 1
osv·2017-01-30·CVSS 9.8
CVE-2016-9132 [CRITICAL] CVE-2016-9132: In Botan 1
In Botan 1.8.0 through 1.11.33, when decoding BER data an integer overflow could occur, which would cause an incorrect length field to be computed. Some API callers may use the returned (incorrect and attacker controlled) length field in a way which later causes memory corruption or other failure.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-9132 botan: Integer overflow in BER decoder [epel-all]
bugzilla·2016-12-02·CVSS 9.8
CVE-2016-9132 [CRITICAL] CVE-2016-9132 botan: Integer overflow in BER decoder [epel-all]
CVE-2016-9132 botan: Integer overflow in BER decoder [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora EP
Bugzilla
CVE-2016-9132 botan: Integer overflow in BER decoder
bugzilla·2016-12-02·CVSS 9.8
CVE-2016-9132 [CRITICAL] CVE-2016-9132 botan: Integer overflow in BER decoder
CVE-2016-9132 botan: Integer overflow in BER decoder
While decoding BER length fields, an integer overflow could occur. This could occur while parsing untrusted inputs such as X.509 certificates. The overflow does not seem to lead to any obviously exploitable condition, but exploitation cannot be positively ruled out. Only 32-bit platforms are likely affected; to cause an overflow on 64-bit the parsed data would have to be many gigabytes.
Upstream patch:
https://github.com/randombit/botan/commit/987ad747db6d0d7e36f840398f3cf02e2fbfd90f
Discussion:
Created botan tracking bugs for this issue:
Affects: fedora-all [bug 1400895]
Affects: epel-all [bug 1400896]
Bugzilla
CVE-2016-9132 botan: Integer overflow in BER decoder [fedora-all]
bugzilla·2016-12-02·CVSS 9.8
CVE-2016-9132 [CRITICAL] CVE-2016-9132 botan: Integer overflow in BER decoder [fedora-all]
CVE-2016-9132 botan: Integer overflow in BER decoder [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. Whil
http://www.securityfocus.com/bid/95879https://github.com/randombit/botan/commit/987ad747db6d0d7e36f840398f3cf02e2fbfd90fhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4OUDGVRQYQUL7F5MRP3LAV7EHRJG4BBE/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z2Y3JLMTE3VIV4X5X6SXVZTJBDDLCS3D/http://www.securityfocus.com/bid/95879https://github.com/randombit/botan/commit/987ad747db6d0d7e36f840398f3cf02e2fbfd90fhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4OUDGVRQYQUL7F5MRP3LAV7EHRJG4BBE/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z2Y3JLMTE3VIV4X5X6SXVZTJBDDLCS3D/
2017-01-30
Published