Описание
Security update for Botan
This update for Botan fixes the following issues:
- CVE-2026-34582: Fixed a client authentication bypass in TLS 1.3 implementation (bsc#1261880)
Список пакетов
openSUSE Leap 16.0
Botan-3.7.1-160000.3.1
Botan-doc-3.7.1-160000.3.1
libbotan-3-7-3.7.1-160000.3.1
libbotan-devel-3.7.1-160000.3.1
python3-botan-3.7.1-160000.3.1
Ссылки
- SUSE Security Ratings
- SUSE Bug 1261880
- SUSE CVE CVE-2026-34582 page
Описание
Botan is a C++ cryptography library. Prior to version 3.11.1, the TLS 1.3 implementation allowed ApplicationData records to be processed prior to the Finished message being received. A server which is attempting to enforce client authentication via certificates can by bypassed by a client which entirely omits Certificate, CertificateVerify, and the Finished message and instead sends application data records. This vulnerability is fixed in 3.11.1.
Затронутые продукты
openSUSE Leap 16.0:Botan-3.7.1-160000.3.1
openSUSE Leap 16.0:Botan-doc-3.7.1-160000.3.1
openSUSE Leap 16.0:libbotan-3-7-3.7.1-160000.3.1
openSUSE Leap 16.0:libbotan-devel-3.7.1-160000.3.1
Ссылки
- CVE-2026-34582
- SUSE Bug 1261880