Логотип exploitDog
bind: "CVE-2024-34702"
Консоль
Логотип exploitDog

exploitDog

bind: "CVE-2024-34702"

Количество 6

Количество 6

ubuntu логотип

CVE-2024-34702

около 1 года назад

Botan is a C++ cryptography library. X.509 certificates can identify elliptic curves using either an object identifier or using explicit encoding of the parameters. Prior to 3.5.0 and 2.19.5, checking name constraints in X.509 certificates is quadratic in the number of names and name constraints. An attacker who presented a certificate chain which contained a very large number of names in the SubjectAlternativeName, signed by a CA certificate which contained a large number of name constraints, could cause a denial of service. The problem has been addressed in Botan 3.5.0 and a partial backport has also been applied and is included in Botan 2.19.5.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2024-34702

около 1 года назад

Botan is a C++ cryptography library. X.509 certificates can identify elliptic curves using either an object identifier or using explicit encoding of the parameters. Prior to 3.5.0 and 2.19.5, checking name constraints in X.509 certificates is quadratic in the number of names and name constraints. An attacker who presented a certificate chain which contained a very large number of names in the SubjectAlternativeName, signed by a CA certificate which contained a large number of name constraints, could cause a denial of service. The problem has been addressed in Botan 3.5.0 and a partial backport has also been applied and is included in Botan 2.19.5.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2024-34702

около 1 года назад

Botan is a C++ cryptography library. X.509 certificates can identify e ...

CVSS3: 5.3
EPSS: Низкий
fstec логотип

BDU:2024-07764

больше 1 года назад

Уязвимость криптографической библиотеки C++ Botan, связанная с асимметричным потреблением ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 5.3
EPSS: Низкий
redos логотип

ROS-20241001-13

12 месяцев назад

Множественные уязвимости botan2

CVSS3: 5.3
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2024:0201-1

около 1 года назад

Security update for Botan

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2024-34702

Botan is a C++ cryptography library. X.509 certificates can identify elliptic curves using either an object identifier or using explicit encoding of the parameters. Prior to 3.5.0 and 2.19.5, checking name constraints in X.509 certificates is quadratic in the number of names and name constraints. An attacker who presented a certificate chain which contained a very large number of names in the SubjectAlternativeName, signed by a CA certificate which contained a large number of name constraints, could cause a denial of service. The problem has been addressed in Botan 3.5.0 and a partial backport has also been applied and is included in Botan 2.19.5.

CVSS3: 5.3
0%
Низкий
около 1 года назад
nvd логотип
CVE-2024-34702

Botan is a C++ cryptography library. X.509 certificates can identify elliptic curves using either an object identifier or using explicit encoding of the parameters. Prior to 3.5.0 and 2.19.5, checking name constraints in X.509 certificates is quadratic in the number of names and name constraints. An attacker who presented a certificate chain which contained a very large number of names in the SubjectAlternativeName, signed by a CA certificate which contained a large number of name constraints, could cause a denial of service. The problem has been addressed in Botan 3.5.0 and a partial backport has also been applied and is included in Botan 2.19.5.

CVSS3: 5.3
0%
Низкий
около 1 года назад
debian логотип
CVE-2024-34702

Botan is a C++ cryptography library. X.509 certificates can identify e ...

CVSS3: 5.3
0%
Низкий
около 1 года назад
fstec логотип
BDU:2024-07764

Уязвимость криптографической библиотеки C++ Botan, связанная с асимметричным потреблением ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 5.3
0%
Низкий
больше 1 года назад
redos логотип
ROS-20241001-13

Множественные уязвимости botan2

CVSS3: 5.3
12 месяцев назад
suse-cvrf логотип
openSUSE-SU-2024:0201-1

Security update for Botan

около 1 года назад

Уязвимостей на страницу