cbcvebase.
CVE-2024-39312
published 2024-07-08

CVE-2024-39312: Botan is a C++ cryptography library. X.509 certificates can identify elliptic curves using either an object identifier or using explicit encoding of the…

PriorityP426medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
EPSS
0.27%
19.1th percentile
Botan is a C++ cryptography library. X.509 certificates can identify elliptic curves using either an object identifier or using explicit encoding of the parameters. A bug in the parsing of name constraint extensions in X.509 certificates meant that if the extension included both permitted subtrees and excluded subtrees, only the permitted subtree would be checked. If a certificate included a name which was permitted by the permitted subtree but also excluded by excluded subtree, it would be accepted. Fixed in versions 3.5.0 and 2.19.5.

Affected

9 ranges
VendorProductVersion rangeFixed in
botan_projectbotan< 2.19.52.19.5
botan_projectbotan>= 0 < 2.19.3+dfsg-1+deb12u12.19.3+dfsg-1+deb12u1
botan_projectbotan>= 0 < 2.19.5+dfsg-12.19.5+dfsg-1
botan_projectbotan>= 0 < 2.19.1+dfsg-2ubuntu1+esm12.19.1+dfsg-2ubuntu1+esm1
botan_projectbotan>= 0 < 2.19.3+dfsg-1ubuntu2+esm12.19.3+dfsg-1ubuntu2+esm1
botan_projectbotan>= 3.0.0 < 3.5.03.5.0
debianbotan< botan 2.19.3+dfsg-1+deb12u1 (bookworm)botan 2.19.3+dfsg-1+deb12u1 (bookworm)
randombitbotan< 2.19.52.19.5
randombitbotan

CVSS provenance

nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
osv5.3MEDIUM
vendor_debian5.3MEDIUM
vendor_ubuntu5.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.