CVE-2014-9742

The Miller-Rabin primality check in Botan before 1.10.8 and 1.11.x before 1.11.9 improperly uses a single random base, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via a DH group.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:botan_project:botan:*:*:*:*:*:*:*:*
cpe:2.3:a:botan_project:botan:1.11.0:*:*:*:*:*:*:*
cpe:2.3:a:botan_project:botan:1.11.1:*:*:*:*:*:*:*
cpe:2.3:a:botan_project:botan:1.11.2:*:*:*:*:*:*:*
cpe:2.3:a:botan_project:botan:1.11.3:*:*:*:*:*:*:*
cpe:2.3:a:botan_project:botan:1.11.4:*:*:*:*:*:*:*
cpe:2.3:a:botan_project:botan:1.11.5:*:*:*:*:*:*:*
cpe:2.3:a:botan_project:botan:1.11.6:*:*:*:*:*:*:*
cpe:2.3:a:botan_project:botan:1.11.7:*:*:*:*:*:*:*
cpe:2.3:a:botan_project:botan:1.11.8:*:*:*:*:*:*:*

History

21 Nov 2024, 02:21

Type Values Removed Values Added
References () http://botan.randombit.net/security.html - Vendor Advisory () http://botan.randombit.net/security.html - Vendor Advisory
References () http://marc.info/?l=botan-devel&m=139717503205066&w=2 - Vendor Advisory () http://marc.info/?l=botan-devel&m=139717503205066&w=2 - Vendor Advisory

Information

Published : 2016-05-13 14:59

Updated : 2024-11-21 02:21


NVD link : CVE-2014-9742

Mitre link : CVE-2014-9742

CVE.ORG link : CVE-2014-9742


JSON object : View

Products Affected

botan_project

  • botan
CWE
CWE-310

Cryptographic Issues