- ------------------------------------------------------------------------- Debian LTS Advisory DLA-2812-1 [email protected] https://www.debian.org/lts/security/ Anton Gladky November 08, 2021 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : botan1.10 Version : 1.10.17-1+deb9u1 CVE ID : CVE-2017-14737 One security issue has been discovered in botan1.10: a C++ cryptography library. An attacker of a local or a cross-VM may be able to recover bits of secret exponents as used in RSA, DH, etc. with help of cache analysis. https://www.usenix.org/conference/usenixsecurity17/technical-sessions/presentation/wang-shuai For Debian 9 stretch, this problem has been fixed in version 1.10.17-1+deb9u1. We recommend that you upgrade your botan1.10 packages. For the detailed security status of botan1.10 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/botan1.10 Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS