Botan is a C++ cryptography library. X.509 certificates can identify elliptic curves using either an object identifier or using explicit encoding of the parameters. Prior to 3.5.0 and 2.19.5, checking name constraints in X.509 certificates is quadratic in the number of names and name constraints. An attacker who presented a certificate chain which contained a very large number of names in the SubjectAlternativeName, signed by a CA certificate which contained a large number of name constraints, could cause a denial of service. The problem has been addressed in Botan 3.5.0 and a partial backport has also been applied and is included in Botan 2.19.5.
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade botanUpgrade botan3 | Oct 10, 2024 | Jul 8, 2024 |
| Debian | — | Upgrade botan | May 15, 2025 | Jul 8, 2024 |
| Suse | — | Upgrade libbotan-devel-64bitUpgrade libbotan-2-19-64bitUpgrade libbotan-devel-32bitUpgrade botanUpgrade python3-botanUpgrade libbotan-develUpgrade botan-docUpgrade libbotan-2-19Upgrade libbotan-2-19-32bit | Jul 17, 2024 | Jul 8, 2024 |
| Ubuntu | — | Upgrade libbotan-2-19 (Ubuntu Pro)Upgrade libbotan-2-19Upgrade botan (Ubuntu Pro)Upgrade botanUpgrade python3-botan (Ubuntu Pro)Upgrade libbotan-2-devUpgrade libbotan-2-dev (Ubuntu Pro)Upgrade python3-botan | Jun 26, 2025 | Jul 8, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub