Описание
In Botan before 2.17.3, constant-time computations are not used for certain decoding and encoding operations (base32, base58, base64, and hex).
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| botan | fixed | 2.17.3+dfsg-1 | package | |
| botan | no-dsa | buster | package | |
| botan1.10 | removed | package | ||
| botan1.10 | not-affected | stretch | package |
Примечания
https://github.com/randombit/botan/pull/2549
EPSS
Процентиль: 72%
0.00711
Низкий
Связанные уязвимости
CVSS3: 9.8
ubuntu
почти 5 лет назад
In Botan before 2.17.3, constant-time computations are not used for certain decoding and encoding operations (base32, base58, base64, and hex).
CVSS3: 9.8
nvd
почти 5 лет назад
In Botan before 2.17.3, constant-time computations are not used for certain decoding and encoding operations (base32, base58, base64, and hex).
CVSS3: 9.8
github
больше 3 лет назад
In Botan before 2.17.3, constant-time computations are not used for certain decoding and encoding operations (base32, base58, base64, and hex).
EPSS
Процентиль: 72%
0.00711
Низкий