UBUNTU-CVE-2018-9860
Dashboard / Vulnerabilities / UBUNTU-CVE-2018-9860
Summary:
Details: An issue was discovered in Botan 1.11.32 through 2.x before 2.6.0. An off-by-one error when processing malformed TLS-CBC ciphertext could cause the receiving side to include in the HMAC computation exactly 64K bytes of data following the record buffer, aka an over-read. The MAC comparison will subsequently fail and the connection will be closed. This could be used for denial of service. No information leak occurs.
References: https://ubuntu.com/security/CVE-2018-9860, https://github.com/randombit/botan/commit/ec222c99719c396a1f4756b2ca345dbbfbeb5ed5, https://www.cve.org/CVERecord?id=CVE-2018-9860
Affected packages
Package
Name: botan1.10
Purl: pkg:deb/ubuntu/[email protected]+deb7u1ubuntu0.14.04.1+esm1?arch=source&distro=esm-infra-legacy/trusty
Affected ranges
Type: ECOSYSTEM
Events:
