bcrypt password hashing in Botan before 2.1.0 does not correctly handle passwords with a length between 57 and 72 characters, which makes it easier for attackers to determine the cleartext password.
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Botan | Botan_project | 1.11.0 (including) | 2.1.0 (excluding) |
Botan1.10 | Ubuntu | precise | * |
Botan1.10 | Ubuntu | upstream | * |
Botan1.10 | Ubuntu | yakkety | * |
Botan1.10 | Ubuntu | zesty | * |