In Botan before 2.19.3, it is possible to forge OCSP responses due to a certificate verification error. This issue was introduced in Botan 1.11.34 (November 2016).
CVSS Details
- CVSS 3.1 Base Score: 9.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | alpine-linux-upgrade-botan | Mar 21, 2024 | Nov 27, 2022 | |
| Debian | debian-upgrade-botan | Jul 30, 2024 | Nov 27, 2022 | |
| Suse | — | suse-upgrade-botansuse-upgrade-botan-docsuse-upgrade-libbotan-2-10suse-upgrade-libbotan-2-10-32bitsuse-upgrade-libbotan-2-10-64bitsuse-upgrade-libbotan-2-18suse-upgrade-libbotan-2-18-32bitsuse-upgrade-libbotan-2-18-64bitsuse-upgrade-libbotan-develsuse-upgrade-libbotan-devel-32bitsuse-upgrade-libbotan-devel-64bitsuse-upgrade-python3-botan | Nov 24, 2022 | Nov 23, 2022 |
| Ubuntu | no-fix-ubuntu-package | Jun 26, 2025 | Nov 27, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub