Vulnerability Database

289,871

Total vulnerabilities in the database

CVE-2017-14737

A cryptographic cache-based side channel in the RSA implementation in Botan before 1.10.17, and 1.11.x and 2.x before 2.3.0, allows a local attacker to recover information about RSA secret keys, as demonstrated by CacheD. This occurs because an array is indexed with bits derived from a secret key.

  • Published: Sep 26, 2017
  • Updated: Apr 13, 2023
  • CVE: CVE-2017-14737
  • Severity: Medium
  • Exploit:

CVSS v3:

  • Severity: Medium
  • Score: 5.5
  • AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CVSS v2:

  • Severity: Low
  • Score: 2.1
  • AV:L/AC:L/Au:N/C:P/I:N/A:N

No CWE or OWASP classifications available.

Software From Fixed in
botan_project / botan 1.11.18 1.11.18.x
botan_project / botan 1.11.0 1.11.0.x
botan_project / botan 1.11.21 1.11.21.x
botan_project / botan 1.11.26 1.11.26.x
botan_project / botan 1.11.19 1.11.19.x
botan_project / botan 1.11.12 1.11.12.x
botan_project / botan 1.11.3 1.11.3.x
botan_project / botan 1.11.17 1.11.17.x
botan_project / botan 1.11.10 1.11.10.x
botan_project / botan 1.11.14 1.11.14.x
botan_project / botan 1.11.1 1.11.1.x
botan_project / botan 1.11.6 1.11.6.x
botan_project / botan 1.11.25 1.11.25.x
botan_project / botan 1.11.27 1.11.27.x
botan_project / botan 1.11.11 1.11.11.x
botan_project / botan 1.11.24 1.11.24.x
botan_project / botan 1.11.4 1.11.4.x
botan_project / botan 1.11.7 1.11.7.x
botan_project / botan 1.11.5 1.11.5.x
botan_project / botan 1.11.20 1.11.20.x
botan_project / botan 1.11.33 1.11.33.x
botan_project / botan 1.11.8 1.11.8.x
botan_project / botan 1.11.13 1.11.13.x
botan_project / botan 1.11.28 1.11.28.x
botan_project / botan 1.11.15 1.11.15.x
botan_project / botan 1.11.23 1.11.23.x
botan_project / botan 1.11.9 1.11.9.x
botan_project / botan 2.0.1 2.0.1.x
botan_project / botan 1.11.16 1.11.16.x
botan_project / botan 1.11.2 1.11.2.x
botan_project / botan 1.11.22 1.11.22.x
botan_project / botan - 1.10.16.x
botan_project / botan 1.11.34 1.11.34.x
botan_project / botan 2.0.0 2.0.0.x
botan_project / botan 2.1.0 2.1.0.x
botan_project / botan 2.2.0 2.2.0.x
debian / debian_linux 9.0 9.0.x