668
VMScore

CVE-2017-2801

Published: 24/05/2017 Updated: 19/04/2022
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

A programming error exists in a way Randombit Botan cryptographic library version 2.0.1 implements x500 string comparisons which could lead to certificate verification issues and abuse. A specially crafted X509 certificate would need to be delivered to the client or server application in order to trigger this vulnerability.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

botan project botan 2.0.1

Vendor Advisories

Debian Bug report logs - #860072 botan110: CVE-2017-2801: Incorrect comparison in X509 DN strings Package: src:botan110; Maintainer for src:botan110 is Ondřej Surý <ondrej@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Tue, 11 Apr 2017 05:24:02 UTC Severity: serious Tags: patch, securi ...