Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-39312

Опубликовано: 08 июл. 2024
Источник: debian
EPSS Низкий

Описание

Botan is a C++ cryptography library. X.509 certificates can identify elliptic curves using either an object identifier or using explicit encoding of the parameters. A bug in the parsing of name constraint extensions in X.509 certificates meant that if the extension included both permitted subtrees and excluded subtrees, only the permitted subtree would be checked. If a certificate included a name which was permitted by the permitted subtree but also excluded by excluded subtree, it would be accepted. Fixed in versions 3.5.0 and 2.19.5.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
botanfixed2.19.5+dfsg-1package
botanfixed2.19.3+dfsg-1+deb12u1bookwormpackage
botanno-dsabullseyepackage

Примечания

  • https://github.com/randombit/botan/security/advisories/GHSA-jp24-56jm-gg86

EPSS

Процентиль: 51%
0.00281
Низкий

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 1 года назад

Botan is a C++ cryptography library. X.509 certificates can identify elliptic curves using either an object identifier or using explicit encoding of the parameters. A bug in the parsing of name constraint extensions in X.509 certificates meant that if the extension included both permitted subtrees and excluded subtrees, only the permitted subtree would be checked. If a certificate included a name which was permitted by the permitted subtree but also excluded by excluded subtree, it would be accepted. Fixed in versions 3.5.0 and 2.19.5.

CVSS3: 5.3
nvd
больше 1 года назад

Botan is a C++ cryptography library. X.509 certificates can identify elliptic curves using either an object identifier or using explicit encoding of the parameters. A bug in the parsing of name constraint extensions in X.509 certificates meant that if the extension included both permitted subtrees and excluded subtrees, only the permitted subtree would be checked. If a certificate included a name which was permitted by the permitted subtree but also excluded by excluded subtree, it would be accepted. Fixed in versions 3.5.0 and 2.19.5.

CVSS3: 5.3
fstec
больше 1 года назад

Уязвимость криптографической библиотеки C++ Botan, связанная с неправильной проверкой сертификата, позволяющая нарушителю оказать влияние на целостность системы

suse-cvrf
больше 1 года назад

Security update for Botan

CVSS3: 5.3
redos
больше 1 года назад

Множественные уязвимости botan2

EPSS

Процентиль: 51%
0.00281
Низкий