The Miller-Rabin primality check in Botan before 1.10.8 and 1.11.x before 1.11.9 improperly uses a single random base, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via a DH group.
References
Link | Resource |
---|---|
http://botan.randombit.net/security.html | Vendor Advisory |
http://marc.info/?l=botan-devel&m=139717503205066&w=2 | Vendor Advisory |
http://botan.randombit.net/security.html | Vendor Advisory |
http://marc.info/?l=botan-devel&m=139717503205066&w=2 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 02:21
Type | Values Removed | Values Added |
---|---|---|
References | () http://botan.randombit.net/security.html - Vendor Advisory | |
References | () http://marc.info/?l=botan-devel&m=139717503205066&w=2 - Vendor Advisory |
Information
Published : 2016-05-13 14:59
Updated : 2024-11-21 02:21
NVD link : CVE-2014-9742
Mitre link : CVE-2014-9742
CVE.ORG link : CVE-2014-9742
JSON object : View
Products Affected
botan_project
- botan
CWE
CWE-310
Cryptographic Issues