In Botan 1.11.29 through 1.11.32, RSA decryption with certain padding options had a detectable timing channel which could given sufficient queries be used to recover plaintext, aka an "OAEP side channel" attack.
| Software | From | Fixed in |
|---|---|---|
| botan_project / botan | 1.11.32 | 1.11.32.x |
| botan_project / botan | 1.11.30 | 1.11.30.x |
| botan_project / botan | 1.11.29 | 1.11.29.x |
| botan_project / botan | 1.11.31 | 1.11.31.x |