2.1
CVSSv2

CVE-2017-14737

Published: 26/09/2017 Updated: 15/12/2021
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

A cryptographic cache-based side channel in the RSA implementation in Botan prior to 1.10.17, and 1.11.x and 2.x prior to 2.3.0, allows a local malicious user to recover information about RSA secret keys, as demonstrated by CacheD. This occurs because an array is indexed with bits derived from a secret key.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

botan project botan 1.11.6

botan project botan 1.11.7

botan project botan 1.11.8

botan project botan 1.11.9

botan project botan 1.11.23

botan project botan 1.11.24

botan project botan 1.11.25

botan project botan 1.11.26

botan project botan

botan project botan 1.11.0

botan project botan 1.11.1

botan project botan 1.11.15

botan project botan 1.11.16

botan project botan 1.11.17

botan project botan 1.11.18

botan project botan 2.0.0

botan project botan 2.0.1

botan project botan 2.1.0

botan project botan 2.2.0

botan project botan 1.11.3

botan project botan 1.11.5

botan project botan 1.11.10

botan project botan 1.11.12

botan project botan 1.11.14

botan project botan 1.11.19

botan project botan 1.11.21

botan project botan 1.11.28

botan project botan 1.11.34

botan project botan 1.11.2

botan project botan 1.11.4

botan project botan 1.11.11

botan project botan 1.11.13

botan project botan 1.11.20

botan project botan 1.11.22

botan project botan 1.11.27

botan project botan 1.11.33

debian debian linux 9.0

Vendor Advisories

Debian Bug report logs - #877436 botan110: CVE-2017-14737: A cryptographic cache-based side channel in the RSA implementation allows local attacker to recover information about RSA secret keys Package: src:botan110; Maintainer for src:botan110 is Ondřej Surý <ondrej@debianorg>; Reported by: Salvatore Bonaccorso <carn ...
A cryptographic cache-based side channel in the RSA implementation in Botan before 11017, and 111x and 2x before 230, allows a local attacker to recover information about RSA secret keys, as demonstrated by CacheD This occurs because an array is indexed with bits derived from a secret key ...