A programming error exists in a way Randombit Botan cryptographic library version 2.0.1 implements x500 string comparisons which could lead to certificate verification issues and abuse. A specially crafted X509 certificate would need to be delivered to the client or server application in order to trigger this vulnerability.
The product reads data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/98106 | third party advisory vdb entry us government resource |
http://www.debian.org/security/2017/dsa-3939 | vendor advisory |
http://talosintelligence.com/vulnerability_reports/TALOS-2017-0294 | vdb entry exploit mitigation third party advisory |