Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2016-2849
Description:Botan before 1.10.13 and 1.11.x before 1.11.29 do not use a constant- time algorithm to perform a modular inverse on the signature nonce k, which might allow remote attackers to obtain ECDSA secret keys via a timing side-channel attack.
Test IDs: 1.3.6.1.4.1.25623.1.0.703565   1.3.6.1.4.1.25623.1.1.1.2.2016.449  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2016-2849
Debian Security Information: DSA-3565 (Google Search)
http://www.debian.org/security/2016/dsa-3565
http://lists.fedoraproject.org/pipermail/package-announce/2016-May/183669.html
https://security.gentoo.org/glsa/201701-23
http://marc.info/?l=botan-devel&m=146185420505943&w=2




© 1998-2025 E-Soft Inc. All rights reserved.