7.5
CVSSv2

CVE-2018-9127

Published: 02/04/2018 Updated: 15/05/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Botan 2.2.0 - 2.4.0 (fixed in 2.5.0) improperly handled wildcard certificates and could accept certain certificates as valid for hostnames when, under RFC 6125 rules, they should not match. This only affects certificates issued to the same domain as the host, so to impersonate a host one must already have a wildcard certificate matching other hosts in the same domain. For example, b*.example.com would match some hostnames that do not begin with a 'b' character.

Vulnerable Product Search on Vulmon Subscribe to Product

botan project botan

Vendor Advisories

Debian Bug report logs - #894648 CVE-2018-9127 Package: src:botan; Maintainer for src:botan is Laszlo Boszormenyi (GCS) <gcs@debianorg>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Mon, 2 Apr 2018 20:45:04 UTC Severity: grave Tags: fixed-upstream, security, upstream Found in version botan/240-1 Fixed ...