Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 542
Alerts This Week
Warning Icon 1 542

Debian 7 DLA-915-1 Critical: Botan1.10 Information Leakage Issue

debian lts
Calendar Grey April 25, 2017
Scroller Debian Lts
An enhancement for botan1.10 resolving X509 DN string comparison vulnerabilities on Debian 7, mitigating possible information breaches.
A bug in X509 DN string comparisons could result in out of bound reads

Summary

A bug in X509 DN string comparisons could result in out of bound reads.
This could result in information leakage, denial of service, or
potentially incorrect certificate validation results.


For Debian 7 "Wheezy", these problems have been fixed in version
1.10.5-1+deb7u3.

We recommend that you upgrade your botan1.10 packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS



Severity
critical
Lowest
Low
Medium
High
Critical

Package: botan1.10
Version: 1.10.5-1+deb7u3
CVE ID: CVE-2017-2801
Debian Bug: 860072

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.