Botan before 1.10.13 and 1.11.x before 1.11.22 make it easier for remote attackers to conduct million-message attacks by measuring time differences, related to decoding of PKCS#1 padding.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://lists.fedoraproject.org/pipermail/package-announce/2016-May/183669.html | vendor advisory |
http://www.debian.org/security/2016/dsa-3565 | vendor advisory |
http://marc.info/?l=botan-devel&m=146185420505943&w=2 | vendor advisory mailing list |
http://botan.randombit.net/security.html | vendor advisory |