Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p27h-83pf-6hh9

Опубликовано: 23 окт. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 5.9

Описание

Botan before 3.6.0, when certain LLVM versions are used, has compiler-induced secret-dependent control flow in lib/utils/ghash/ghash.cpp in GHASH in AES-GCM. There is a branch instead of an XOR with carry. This was observed for Clang in LLVM 15 on RISC-V.

Botan before 3.6.0, when certain LLVM versions are used, has compiler-induced secret-dependent control flow in lib/utils/ghash/ghash.cpp in GHASH in AES-GCM. There is a branch instead of an XOR with carry. This was observed for Clang in LLVM 15 on RISC-V.

EPSS

Процентиль: 29%
0.00106
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-203

Связанные уязвимости

CVSS3: 5.9
ubuntu
около 1 года назад

Botan before 3.6.0, when certain LLVM versions are used, has compiler-induced secret-dependent control flow in lib/utils/ghash/ghash.cpp in GHASH in AES-GCM. There is a branch instead of an XOR with carry. This was observed for Clang in LLVM 15 on RISC-V.

CVSS3: 5.9
nvd
около 1 года назад

Botan before 3.6.0, when certain LLVM versions are used, has compiler-induced secret-dependent control flow in lib/utils/ghash/ghash.cpp in GHASH in AES-GCM. There is a branch instead of an XOR with carry. This was observed for Clang in LLVM 15 on RISC-V.

CVSS3: 5.9
debian
около 1 года назад

Botan before 3.6.0, when certain LLVM versions are used, has compiler- ...

CVSS3: 5.9
fstec
около 1 года назад

Уязвимость компонента lib/utils/ghash/ghash.cpp криптографической библиотеки Botan, связанная с раскрытием информации через несоответствие, позволяющая нарушителю получить доступ к конфиденциальным данным

suse-cvrf
около 1 года назад

Security update for Botan

EPSS

Процентиль: 29%
0.00106
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-203