Information Exposure Through Discrepancy Affecting botan package, versions [,3.6.0)
Threat Intelligence
Exploit Maturity
Proof of concept
EPSS
0.05% (17th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-UNMANAGED-BOTAN-8302913
- published 24 Oct 2024
- disclosed 23 Oct 2024
- credit Moritz Schneider, Daniele Lain, Ivan Puddu, Nicolas Dutly, Srdjan Capkun
Introduced: 23 Oct 2024
New CVE-2024-50383 Open this link in a new tabHow to fix?
Upgrade botan
to version 3.6.0 or higher.
Overview
Affected versions of this package are vulnerable to Information Exposure Through Discrepancy due to a compiler-induced secret-dependent operation in donna128
. An attacker can potentially skip an addition operation if a carry is not set by exploiting this vulnerability.
Note:
This is only exploitable if the system uses GCC 11.3.0 with -O2 on MIPS, or GCC on x86-i386, and specifically on 32-bit processors.