4.3
CVSSv2

CVE-2018-20187

Published: 08/03/2019 Updated: 12/03/2019
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.9 | Impact Score: 3.6 | Exploitability Score: 2.2
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

A side-channel issue exists in Botan prior to 2.9.0. An attacker capable of precisely measuring the time taken for ECC key generation may be able to derive information about the high bits of the secret key, as the function to derive the public point from the secret scalar uses an unblinded Montgomery ladder whose loop iteration count depends on the bitlength of the secret. This issue affects only key generation, not ECDSA signatures or ECDH key agreement.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

botan project botan

Vendor Advisories

Debian Bug report logs - #918732 botan: CVE-2018-20187: Side channel during ECC key generation Package: src:botan; Maintainer for src:botan is Laszlo Boszormenyi (GCS) <gcs@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Tue, 8 Jan 2019 20:45:05 UTC Severity: important Tags: security, upstre ...