Show filters
4 Total Results
Displaying 1-4 of 4
Sort by:
Attacker Value
Unknown
CVE-2016-9132
Disclosure Date: January 30, 2017 (last updated November 08, 2023)
In Botan 1.8.0 through 1.11.33, when decoding BER data an integer overflow could occur, which would cause an incorrect length field to be computed. Some API callers may use the returned (incorrect and attacker controlled) length field in a way which later causes memory corruption or other failure.
0
Attacker Value
Unknown
CVE-2015-5727
Disclosure Date: May 13, 2016 (last updated November 25, 2024)
The BER decoder in Botan 1.10.x before 1.10.10 and 1.11.x before 1.11.19 allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors, related to a length field.
0
Attacker Value
Unknown
CVE-2015-5726
Disclosure Date: May 13, 2016 (last updated November 25, 2024)
The BER decoder in Botan 0.10.x before 1.10.10 and 1.11.x before 1.11.19 allows remote attackers to cause a denial of service (application crash) via an empty BIT STRING in ASN.1 data.
0
Attacker Value
Unknown
CVE-2016-2849
Disclosure Date: May 13, 2016 (last updated November 25, 2024)
Botan before 1.10.13 and 1.11.x before 1.11.29 do not use a constant-time algorithm to perform a modular inverse on the signature nonce k, which might allow remote attackers to obtain ECDSA secret keys via a timing side-channel attack.
0