Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-39312

Опубликовано: 08 июл. 2024
Источник: debian
EPSS Низкий

Описание

Botan is a C++ cryptography library. X.509 certificates can identify elliptic curves using either an object identifier or using explicit encoding of the parameters. A bug in the parsing of name constraint extensions in X.509 certificates meant that if the extension included both permitted subtrees and excluded subtrees, only the permitted subtree would be checked. If a certificate included a name which was permitted by the permitted subtree but also excluded by excluded subtree, it would be accepted. Fixed in versions 3.5.0 and 2.19.5.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
botanfixed2.19.5+dfsg-1package
botanfixed2.19.3+dfsg-1+deb12u1bookwormpackage
botanno-dsabullseyepackage

Примечания

  • https://github.com/randombit/botan/security/advisories/GHSA-jp24-56jm-gg86

EPSS

Процентиль: 19%
0.00272
Низкий

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 2 лет назад

Botan is a C++ cryptography library. X.509 certificates can identify elliptic curves using either an object identifier or using explicit encoding of the parameters. A bug in the parsing of name constraint extensions in X.509 certificates meant that if the extension included both permitted subtrees and excluded subtrees, only the permitted subtree would be checked. If a certificate included a name which was permitted by the permitted subtree but also excluded by excluded subtree, it would be accepted. Fixed in versions 3.5.0 and 2.19.5.

CVSS3: 5.3
nvd
около 2 лет назад

Botan is a C++ cryptography library. X.509 certificates can identify elliptic curves using either an object identifier or using explicit encoding of the parameters. A bug in the parsing of name constraint extensions in X.509 certificates meant that if the extension included both permitted subtrees and excluded subtrees, only the permitted subtree would be checked. If a certificate included a name which was permitted by the permitted subtree but also excluded by excluded subtree, it would be accepted. Fixed in versions 3.5.0 and 2.19.5.

CVSS3: 5.3
fstec
около 2 лет назад

Уязвимость криптографической библиотеки C++ Botan, связанная с неправильной проверкой сертификата, позволяющая нарушителю оказать влияние на целостность системы

suse-cvrf
около 2 лет назад

Security update for Botan

CVSS3: 5.3
redos
почти 2 года назад

Множественные уязвимости botan2

EPSS

Процентиль: 19%
0.00272
Низкий