VendorsBotan Projectbotan1.11.29
Vulnerabilities

Botan Project Botan 1.11.29

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2016-9132
In Botan 1.8.0 through 1.11.33, when decoding BER data an integer overflow could occur, which would cause an incorrect length field to be computed. Some API callers may use the returned (incorrect and attacker controlled) length field in a way which later causes memory corruption or other failure.
Published 2017-01-30 · Modified
9.8EPSS 0.020
CVE-2016-6879
The X509_Certificate::allowed_usage function in botan 1.11.x before 1.11.31 might allow attackers to have unspecified impact by leveraging a call with more than one Key_Usage set in the enum value.
Published 2017-04-10 · Modified
7.5EPSS 0.006
CVE-2016-8871
In Botan 1.11.29 through 1.11.32, RSA decryption with certain padding options had a detectable timing channel which could given sufficient queries be used to recover plaintext, aka an "OAEP side channel" attack.
Published 2016-10-28 · Modified
6.2EPSS 0.004