SUSE-SU-2017:1305-1
Dashboard / Vulnerabilities / SUSE-SU-2017:1305-1
SUSE-SU-2017:1305-1
Summary: Security update for Botan
Details: This update for Botan fixes the following issues: - CVE-2015-7827: PKCS #1 v1.5 decoding was not constant time, it could be used to mount a Bleichenbacher million-message attack (bsc#968030) - CVE-2016-9132: While decoding BER length fields, an integer overflow could occur leading to a denial-of-service (bsc#1013209)
References: https://www.suse.com/support/update/announcement/2017/suse-su-20171305-1/, https://bugzilla.suse.com/1013209, https://bugzilla.suse.com/968030, https://www.suse.com/security/cve/CVE-2015-7827, https://www.suse.com/security/cve/CVE-2016-9132
Affected packages
Package
Name: Botan
Purl: pkg:rpm/suse/Botan&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2011%20SP4
Affected ranges
Type: ECOSYSTEM
Events:
