Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-2850

Опубликовано: 13 мая 2016
Источник: debian

Описание

Botan 1.11.x before 1.11.29 does not enforce TLS policy for (1) signature algorithms and (2) ECC curves, which allows remote attackers to conduct downgrade attacks via unspecified vectors.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
botan1.10not-affectedpackage

Примечания

  • Introduced in 1.11.0, fixed in 1.11.29

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 9 лет назад

Botan 1.11.x before 1.11.29 does not enforce TLS policy for (1) signature algorithms and (2) ECC curves, which allows remote attackers to conduct downgrade attacks via unspecified vectors.

CVSS3: 7.5
nvd
больше 9 лет назад

Botan 1.11.x before 1.11.29 does not enforce TLS policy for (1) signature algorithms and (2) ECC curves, which allows remote attackers to conduct downgrade attacks via unspecified vectors.

CVSS3: 7.5
github
больше 3 лет назад

Botan 1.11.x before 1.11.29 does not enforce TLS policy for (1) signature algorithms and (2) ECC curves, which allows remote attackers to conduct downgrade attacks via unspecified vectors.