5
CVSSv2

CVE-2015-7827

Published: 13/05/2016 Updated: 09/06/2016
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Botan prior to 1.10.13 and 1.11.x prior to 1.11.22 make it easier for remote malicious users to conduct million-message attacks by measuring time differences, related to decoding of PKCS#1 padding.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

fedoraproject fedora 24

botan project botan 1.11.20

botan project botan 1.11.15

botan project botan 1.11.13

botan project botan 1.11.6

botan project botan 1.11.4

botan project botan 1.11.11

botan project botan 1.11.10

botan project botan 1.11.9

botan project botan 1.11.8

botan project botan 1.11.19

botan project botan 1.11.18

botan project botan 1.11.17

botan project botan 1.11.16

botan project botan 1.11.2

botan project botan 1.11.1

botan project botan 1.11.0

botan project botan

botan project botan 1.11.21

botan project botan 1.11.14

botan project botan 1.11.12

botan project botan 1.11.7

botan project botan 1.11.5

botan project botan 1.11.3

debian debian linux 8.0

Vendor Advisories

Debian Bug report logs - #817932 botan110: CVE-2015-7827: PKCS #1 v15 decoding was not constant time Package: src:botan110; Maintainer for src:botan110 is Ondřej Surý <ondrej@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 11 Mar 2016 18:39:02 UTC Severity: important Tags: fixed-up ...