cbcvebase.
CVE-2024-34703
published 2024-06-30

CVE-2024-34703: Botan is a C++ cryptography library. X.509 certificates can identify elliptic curves using either an object identifier or using explicit encoding of the…

PriorityP340high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.50%
39.5th percentile
Botan is a C++ cryptography library. X.509 certificates can identify elliptic curves using either an object identifier or using explicit encoding of the parameters. Prior to versions 3.3.0 and 2.19.4, an attacker could present an ECDSA X.509 certificate using explicit encoding where the parameters are very large. The proof of concept used a 16Kbit prime for this purpose. When parsing, the parameter is checked to be prime, causing excessive computation. This was patched in 2.19.4 and 3.3.0 to allow the prime parameter of the elliptic curve to be at most 521 bits. No known workarounds are available. Note that support for explicit encoding of elliptic curve parameters is deprecated in Botan.

Affected

7 ranges
VendorProductVersion rangeFixed in
botan_projectbotan>= 0 < 2.19.3+dfsg-1+deb12u12.19.3+dfsg-1+deb12u1
botan_projectbotan>= 0 < 2.19.4+dfsg-12.19.4+dfsg-1
botan_projectbotan>= 0 < 2.19.1+dfsg-2ubuntu1+esm12.19.1+dfsg-2ubuntu1+esm1
botan_projectbotan>= 0 < 2.19.3+dfsg-1ubuntu2+esm12.19.3+dfsg-1ubuntu2+esm1
debianbotan< botan 2.19.3+dfsg-1+deb12u1 (bookworm)botan 2.19.3+dfsg-1+deb12u1 (bookworm)
randombitbotan< 2.19.42.19.4
randombitbotan

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
vendor_ubuntu5.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.