Botan is a C++ cryptography library. X.509 certificates can identify elliptic curves using either an object identifier or using explicit encoding of the parameters. Prior to versions 3.3.0 and 2.19.4, an attacker could present an ECDSA X.509 certificate using explicit encoding where the parameters are very large. The proof of concept used a 16Kbit prime for this purpose. When parsing, the parameter is checked to be prime, causing excessive computation. This was patched in 2.19.4 and 3.3.0 to allow the prime parameter of the elliptic curve to be at most 521 bits. No known workarounds are available. Note that support for explicit encoding of elliptic curve parameters is deprecated in Botan.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade botan | Oct 10, 2024 | Jun 30, 2024 |
| Debian | — | Upgrade botan | May 15, 2025 | Jun 30, 2024 |
| Suse | — | Upgrade MozillaThunderbirdUpgrade libbotan-2-19-32bitUpgrade libbotan-devel-64bitUpgrade libbotan-2-19-64bitUpgrade MozillaThunderbird-translations-otherUpgrade MozillaThunderbird-translations-commonUpgrade libbotan-devel-32bitUpgrade libbotan-2-19Upgrade botan-docUpgrade libbotan-develUpgrade botanUpgrade python3-botan | Jul 15, 2024 | Jun 30, 2024 |
| Ubuntu | — | Upgrade botanUpgrade botan (Ubuntu Pro)Upgrade libbotan-2-19 (Ubuntu Pro)Upgrade libbotan-2-dev (Ubuntu Pro)Upgrade libbotan-2-devUpgrade libbotan-2-19Upgrade python3-botan (Ubuntu Pro)Upgrade python3-botan | Jun 26, 2025 | Jun 30, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub