In Botan before 2.17.3, constant-time computations are not used for certain decoding and encoding operations (base32, base58, base64, and hex).
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade botan | Mar 26, 2024 | Feb 22, 2021 |
| Debian | — | Upgrade botan | Jul 30, 2024 | Feb 22, 2021 |
| Suse | — | Upgrade libbotan-2-10Upgrade libbotan-2-10-32bitUpgrade libbotan-develUpgrade botanUpgrade python3-botanUpgrade libbotan-devel-32bitUpgrade botan-doc | May 26, 2021 | Feb 22, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub