CVE-2024-34702
published 2024-07-08CVE-2024-34702: Botan is a C++ cryptography library. X.509 certificates can identify elliptic curves using either an object identifier or using explicit encoding of the…
PriorityP426medium5.3CVSS 3.1
AVNACLPRNUINSUCNINAL
EPSS
0.84%
53.9th percentile
Botan is a C++ cryptography library. X.509 certificates can identify elliptic curves using either an object identifier or using explicit encoding of the parameters. Prior to 3.5.0 and 2.19.5, checking name constraints in X.509 certificates is quadratic in the number of names and name constraints. An attacker who presented a certificate chain which contained a very large number of names in the SubjectAlternativeName, signed by a CA certificate which contained a large number of name constraints, could cause a denial of service. The problem has been addressed in Botan 3.5.0 and a partial backport has also been applied and is included in Botan 2.19.5.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| botan_project | botan | >= 0 < 2.19.3+dfsg-1+deb12u1 | 2.19.3+dfsg-1+deb12u1 |
| botan_project | botan | >= 0 < 2.19.5+dfsg-1 | 2.19.5+dfsg-1 |
| botan_project | botan | >= 0 < 2.19.1+dfsg-2ubuntu1+esm1 | 2.19.1+dfsg-2ubuntu1+esm1 |
| botan_project | botan | >= 0 < 2.19.3+dfsg-1ubuntu2+esm1 | 2.19.3+dfsg-1ubuntu2+esm1 |
| debian | botan | < botan 2.19.3+dfsg-1+deb12u1 (bookworm) | botan 2.19.3+dfsg-1+deb12u1 (bookworm) |
| randombit | botan | < 2.19.5 | 2.19.5 |
| randombit | botan | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
osv5.3MEDIUM
vendor_debian5.3MEDIUM
vendor_ubuntu5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
botan vulnerabilities
osv·2025-06-23·CVSS 5.3
CVE-2024-50382 [MEDIUM] botan vulnerabilities
botan vulnerabilities
It was discovered that Botan could have compiler dependent operations
induced under certain circumstances. An attacker could possibly use this
issue to cause undefined behavior. (CVE-2024-50382, CVE-2024-50383)
Bing Shi discovered that Botan did not limit the size of certain inputs
when checking primality and name constraints. An attacker could possibly
use this issue to cause a denial of service. (CVE-2024-34702,
CVE-2024-34703)
It was discovered that Botan did not correctly handle conflicting name
constraints. An attacker could possibly use this issue to bypass
authentication. (CVE-2024-39312)
OSV
CVE-2024-34702: Botan is a C++ cryptography library
osv·2024-07-08·CVSS 5.3
CVE-2024-34702 [MEDIUM] CVE-2024-34702: Botan is a C++ cryptography library
Botan is a C++ cryptography library. X.509 certificates can identify elliptic curves using either an object identifier or using explicit encoding of the parameters. Prior to 3.5.0 and 2.19.5, checking name constraints in X.509 certificates is quadratic in the number of names and name constraints. An attacker who presented a certificate chain which contained a very large number of names in the SubjectAlternativeName, signed by a CA certificate which contained a large number of name constraints, could cause a denial of service. The problem has been addressed in Botan 3.5.0 and a partial backport has also been applied and is included in Botan 2.19.5.
Ubuntu
Botan vulnerabilities
vendor_ubuntu·2025-06-23·CVSS 5.3
CVE-2024-50382 [MEDIUM] Botan vulnerabilities
Title: Botan vulnerabilities
Summary: Several security issues were fixed in Botan.
It was discovered that Botan could have compiler dependent operations
induced under certain circumstances. An attacker could possibly use this
issue to cause undefined behavior. (CVE-2024-50382, CVE-2024-50383)
Bing Shi discovered that Botan did not limit the size of certain inputs
when checking primality and name constraints. An attacker could possibly
use this issue to cause a denial of service. (CVE-2024-34702,
CVE-2024-34703)
It was discovered that Botan did not correctly handle conflicting name
constraints. An attacker could possibly use this issue to bypass
authentication. (CVE-2024-39312)
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2024-34702: botan - Botan is a C++ cryptography library. X.509 certificates can identify elliptic cu...
vendor_debian·2024·CVSS 5.3
CVE-2024-34702 [MEDIUM] CVE-2024-34702: botan - Botan is a C++ cryptography library. X.509 certificates can identify elliptic cu...
Botan is a C++ cryptography library. X.509 certificates can identify elliptic curves using either an object identifier or using explicit encoding of the parameters. Prior to 3.5.0 and 2.19.5, checking name constraints in X.509 certificates is quadratic in the number of names and name constraints. An attacker who presented a certificate chain which contained a very large number of names in the SubjectAlternativeName, signed by a CA certificate which contained a large number of name constraints, could cause a denial of service. The problem has been addressed in Botan 3.5.0 and a partial backport has also been applied and is included in Botan 2.19.5.
Scope: local
bookworm: resolved (fixed in 2.19.3+dfsg-1+deb12u1)
bullseye: open
trixie: resolved (fixed in 2.19.5+dfsg-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/randombit/botan/commit/21dccc8fef18c165ba3301d850ac61521f85637ehttps://github.com/randombit/botan/commit/39535f13c322f56aa3da2f44b2b6abb8619a82achttps://github.com/randombit/botan/commit/477822a2d10f02d8ba46c9d8a5132f25843f5cc1https://github.com/randombit/botan/commit/7606d70d3a2ac7114476ec2651ca0243c4536fdfhttps://github.com/randombit/botan/commit/c3264821b9f6286ee4e6e3e06826f6b7177e6d41https://github.com/randombit/botan/commit/ff704b12e6fa351aaedd07bffdc91722e84586b8https://github.com/randombit/botan/pull/4034https://github.com/randombit/botan/pull/4045https://github.com/randombit/botan/pull/4047https://github.com/randombit/botan/pull/4052https://github.com/randombit/botan/pull/4186https://github.com/randombit/botan/pull/4187https://github.com/randombit/botan/security/advisories/GHSA-5gg9-hqpr-r58jhttps://github.com/randombit/botan/commit/21dccc8fef18c165ba3301d850ac61521f85637ehttps://github.com/randombit/botan/commit/39535f13c322f56aa3da2f44b2b6abb8619a82achttps://github.com/randombit/botan/commit/477822a2d10f02d8ba46c9d8a5132f25843f5cc1https://github.com/randombit/botan/commit/7606d70d3a2ac7114476ec2651ca0243c4536fdfhttps://github.com/randombit/botan/commit/c3264821b9f6286ee4e6e3e06826f6b7177e6d41https://github.com/randombit/botan/commit/ff704b12e6fa351aaedd07bffdc91722e84586b8https://github.com/randombit/botan/pull/4034https://github.com/randombit/botan/pull/4045https://github.com/randombit/botan/pull/4047https://github.com/randombit/botan/pull/4052https://github.com/randombit/botan/pull/4186https://github.com/randombit/botan/pull/4187https://github.com/randombit/botan/security/advisories/GHSA-5gg9-hqpr-r58j
2024-07-08
Published