Vulnerability Description
In Botan 1.11.29 through 1.11.32, RSA decryption with certain padding options had a detectable timing channel which could given sufficient queries be used to recover plaintext, aka an "OAEP side channel" attack.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Botan Project | Botan | 1.11.29 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/94225Third Party AdvisoryVDB Entry
- https://botan.randombit.net/security.htmlVendor Advisory
- http://www.securityfocus.com/bid/94225Third Party AdvisoryVDB Entry
- https://botan.randombit.net/security.htmlVendor Advisory
FAQ
What is CVE-2016-8871?
CVE-2016-8871 is a vulnerability with a CVSS score of 6.2 (MEDIUM). In Botan 1.11.29 through 1.11.32, RSA decryption with certain padding options had a detectable timing channel which could given sufficient queries be used to recover plaintext, aka an "OAEP side chann...
How severe is CVE-2016-8871?
CVE-2016-8871 has been rated MEDIUM with a CVSS base score of 6.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-8871?
Check the references section above for vendor advisories and patch information. Affected products include: Botan Project Botan.