Botan Project Botan 2.11.0

CPE Details

Botan Project Botan 2.11.0
2.11.0
2019-09-11
16h35 +00:00
2019-09-11
16h35 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:botan_project:botan:2.11.0:*:*:*:*:*:*:*

Informations

Vendor

botan_project

Product

botan

Version

2.11.0

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2024-39312 2024-07-08 16h30 +00:00 Botan is a C++ cryptography library. X.509 certificates can identify elliptic curves using either an object identifier or using explicit encoding of the parameters. A bug in the parsing of name constraint extensions in X.509 certificates meant that if the extension included both permitted subtrees and excluded subtrees, only the permitted subtree would be checked. If a certificate included a name which was permitted by the permitted subtree but also excluded by excluded subtree, it would be accepted. Fixed in versions 3.5.0 and 2.19.5.
5.3
Medium
CVE-2022-43705 2022-11-26 23h00 +00:00 In Botan before 2.19.3, it is possible to forge OCSP responses due to a certificate verification error. This issue was introduced in Botan 1.11.34 (November 2016).
9.1
Critical
CVE-2021-40529 2021-09-06 16h45 +00:00 The ElGamal implementation in Botan through 2.18.1, as used in Thunderbird and other products, allows plaintext recovery because, during interaction between two cryptographic libraries, a certain dangerous combination of the prime defined by the receiver's public key, the generator defined by the receiver's public key, and the sender's ephemeral exponents can lead to a cross-configuration attack against OpenPGP.
5.9
Medium
CVE-2021-24115 2021-02-22 00h57 +00:00 In Botan before 2.17.3, constant-time computations are not used for certain decoding and encoding operations (base32, base58, base64, and hex).
9.8
Critical