Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2017-14737

Опубликовано: 26 сент. 2017
Источник: ubuntu
Приоритет: medium
CVSS2: 2.1
CVSS3: 5.5

Описание

A cryptographic cache-based side channel in the RSA implementation in Botan before 1.10.17, and 1.11.x and 2.x before 2.3.0, allows a local attacker to recover information about RSA secret keys, as demonstrated by CacheD. This occurs because an array is indexed with bits derived from a secret key.

РелизСтатусПримечание
artful

ignored

end of life
bionic

not-affected

1.10.17-0.1
cosmic

not-affected

1.10.17-0.1
devel

DNE

disco

DNE

eoan

DNE

esm-apps/bionic

not-affected

1.10.17-0.1
esm-apps/xenial

needed

esm-infra-legacy/trusty

released

1.10.5-1+deb7u1ubuntu0.14.04.1+esm1
esm-infra/focal

DNE

Показывать по

2.1 Low

CVSS2

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
nvd
больше 8 лет назад

A cryptographic cache-based side channel in the RSA implementation in Botan before 1.10.17, and 1.11.x and 2.x before 2.3.0, allows a local attacker to recover information about RSA secret keys, as demonstrated by CacheD. This occurs because an array is indexed with bits derived from a secret key.

CVSS3: 5.5
debian
больше 8 лет назад

A cryptographic cache-based side channel in the RSA implementation in ...

suse-cvrf
больше 8 лет назад

Security update for Botan

CVSS3: 5.5
github
больше 3 лет назад

A cryptographic cache-based side channel in the RSA implementation in Botan before 1.10.17, and 1.11.x and 2.x before 2.3.0, allows a local attacker to recover information about RSA secret keys, as demonstrated by CacheD. This occurs because an array is indexed with bits derived from a secret key.

2.1 Low

CVSS2

5.5 Medium

CVSS3