5.9
CVSSv3

CVE-2018-12435

Published: 15/06/2018 Updated: 22/08/2018
CVSS v2 Base Score: 1.9 | Impact Score: 2.9 | Exploitability Score: 3.4
CVSS v3 Base Score: 5.9 | Impact Score: 4 | Exploitability Score: 1.4
VMScore: 169
Vector: AV:L/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

Botan 2.5.0 up to and including 2.6.0 prior to 2.7.0 allows a memory-cache side-channel attack on ECDSA signatures, aka the Return Of the Hidden Number Problem or ROHNP, related to dsa/dsa.cpp, ec_group/ec_group.cpp, and ecdsa/ecdsa.cpp. To discover an ECDSA key, the attacker needs access to either the local machine or a different virtual machine on the same physical host.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

botan project botan

Vendor Advisories

Debian Bug report logs - #901619 botan: CVE-2018-12435: memory-cache side-channel attack on ECDSA signatures Package: src:botan; Maintainer for src:botan is Laszlo Boszormenyi (GCS) <gcs@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 15 Jun 2018 17:33:02 UTC Severity: grave Tags: patch, ...