CVE Vulnerabilities

CVE-2017-14737

Published: Sep 26, 2017 | Modified: Dec 15, 2021
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

A cryptographic cache-based side channel in the RSA implementation in Botan before 1.10.17, and 1.11.x and 2.x before 2.3.0, allows a local attacker to recover information about RSA secret keys, as demonstrated by CacheD. This occurs because an array is indexed with bits derived from a secret key.

Affected Software

Name Vendor Start Version End Version
Botan Botan_project * 1.10.16
Botan Botan_project 1.11.0 1.11.0
Botan Botan_project 1.11.1 1.11.1
Botan Botan_project 1.11.2 1.11.2
Botan Botan_project 1.11.3 1.11.3
Botan Botan_project 1.11.4 1.11.4
Botan Botan_project 1.11.5 1.11.5
Botan Botan_project 1.11.6 1.11.6
Botan Botan_project 1.11.7 1.11.7
Botan Botan_project 1.11.8 1.11.8
Botan Botan_project 1.11.9 1.11.9
Botan Botan_project 1.11.10 1.11.10
Botan Botan_project 1.11.11 1.11.11
Botan Botan_project 1.11.12 1.11.12
Botan Botan_project 1.11.13 1.11.13
Botan Botan_project 1.11.14 1.11.14
Botan Botan_project 1.11.15 1.11.15
Botan Botan_project 1.11.16 1.11.16
Botan Botan_project 1.11.17 1.11.17
Botan Botan_project 1.11.18 1.11.18
Botan Botan_project 1.11.19 1.11.19
Botan Botan_project 1.11.20 1.11.20
Botan Botan_project 1.11.21 1.11.21
Botan Botan_project 1.11.22 1.11.22
Botan Botan_project 1.11.23 1.11.23
Botan Botan_project 1.11.24 1.11.24
Botan Botan_project 1.11.25 1.11.25
Botan Botan_project 1.11.26 1.11.26
Botan Botan_project 1.11.27 1.11.27
Botan Botan_project 1.11.28 1.11.28
Botan Botan_project 1.11.33 1.11.33
Botan Botan_project 1.11.34 1.11.34
Botan Botan_project 2.0.0 2.0.0
Botan Botan_project 2.0.1 2.0.1
Botan Botan_project 2.1.0 2.1.0
Botan Botan_project 2.2.0 2.2.0

References