SUSE-SU-2017:2855-1
Dashboard / Vulnerabilities / SUSE-SU-2017:2855-1
SUSE-SU-2017:2855-1
Summary: Security update for Botan
Details: This update for Botan fixes the following issues: This security issue was fixed: - CVE-2017-14737: A cryptographic cache-based side channel in the RSA implementation in Botan allowed a local attacker to recover information about RSA secret keys, as demonstrated by CacheD. This occured because an array is indexed with bits derived from a secret key (bsc#1060433).
References: https://www.suse.com/support/update/announcement/2017/suse-su-20172855-1/, https://bugzilla.suse.com/1060433, https://www.suse.com/security/cve/CVE-2017-14737
Affected packages
Package
Name: Botan
Purl: pkg:rpm/suse/Botan&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP2
Affected ranges
Type: ECOSYSTEM
Events:
