Vulnerability Database

289,871

Total vulnerabilities in the database

CVE-2016-2849

Botan before 1.10.13 and 1.11.x before 1.11.29 do not use a constant-time algorithm to perform a modular inverse on the signature nonce k, which might allow remote attackers to obtain ECDSA secret keys via a timing side-channel attack.

  • Published: May 13, 2016
  • Updated: Apr 13, 2023
  • CVE: CVE-2016-2849
  • Severity: High
  • Exploit:

CVSS v3:

  • Severity: High
  • Score: 7.5
  • AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CVSS v2:

  • Severity: Medium
  • Score: 5
  • AV:N/AC:L/Au:N/C:P/I:N/A:N

CWEs:

Software From Fixed in
debian / debian_linux 8.0 8.0.x
fedoraproject / fedora 24 24.x
botan_project / botan 1.11.18 1.11.18.x
botan_project / botan 1.11.0 1.11.0.x
botan_project / botan 1.11.21 1.11.21.x
botan_project / botan 1.11.26 1.11.26.x
botan_project / botan 1.11.19 1.11.19.x
botan_project / botan 1.10.12 1.10.12.x
botan_project / botan 1.11.12 1.11.12.x
botan_project / botan 1.11.3 1.11.3.x
botan_project / botan 1.11.17 1.11.17.x
botan_project / botan 1.11.10 1.11.10.x
botan_project / botan 1.11.14 1.11.14.x
botan_project / botan 1.11.1 1.11.1.x
botan_project / botan 1.11.6 1.11.6.x
botan_project / botan 1.11.25 1.11.25.x
botan_project / botan 1.11.27 1.11.27.x
botan_project / botan 1.11.11 1.11.11.x
botan_project / botan 1.11.24 1.11.24.x
botan_project / botan 1.11.4 1.11.4.x
botan_project / botan 1.11.7 1.11.7.x
botan_project / botan 1.11.5 1.11.5.x
botan_project / botan 1.11.20 1.11.20.x
botan_project / botan 1.11.8 1.11.8.x
botan_project / botan 1.11.13 1.11.13.x
botan_project / botan 1.11.28 1.11.28.x
botan_project / botan 1.11.15 1.11.15.x
botan_project / botan 1.11.23 1.11.23.x
botan_project / botan 1.11.9 1.11.9.x
botan_project / botan 1.11.16 1.11.16.x
botan_project / botan 1.11.2 1.11.2.x
botan_project / botan 1.11.22 1.11.22.x