Botan is a C++ cryptography library. X.509 certificates can identify elliptic curves using either an object identifier or using explicit encoding of the parameters. Prior to 3.5.0 and 2.19.5, checking name constraints in X.509 certificates is quadratic in the number of names and name constraints. An attacker who presented a certificate chain which contained a very large number of names in the SubjectAlternativeName, signed by a CA certificate which contained a large number of name constraints, could cause a denial of service. The problem has been addressed in Botan 3.5.0 and a partial backport has also been applied and is included in Botan 2.19.5.
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade botanUpgrade botan3 | Oct 10, 2024 | Jul 8, 2024 |
| Debian | — | Upgrade botan | May 15, 2025 | Jul 8, 2024 |
| Suse | — | Upgrade botan-docUpgrade libbotan-2-19-32bitUpgrade libbotan-2-19Upgrade libbotan-devel-64bitUpgrade libbotan-2-19-64bitUpgrade botanUpgrade libbotan-devel-32bitUpgrade python3-botanUpgrade libbotan-devel | Jul 17, 2024 | Jul 8, 2024 |
| Ubuntu | — | Upgrade python3-botanUpgrade libbotan-2-dev (Ubuntu Pro)Upgrade libbotan-2-devUpgrade botanUpgrade python3-botan (Ubuntu Pro)Upgrade libbotan-2-19 (Ubuntu Pro)Upgrade botan (Ubuntu Pro)Upgrade libbotan-2-19 | Jun 26, 2025 | Jul 8, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub