Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Fedora 31: BOTAN2 Security Advisory For CBC Padding Side Channel

fedora
Calendar Grey July 12, 2020
Dist Fedora Esm H88
Update addresses CBC padding vulnerability in botan2 for Fedora 31. Discover key details about this crucial enhancement.
Backport patch for #1849743 (CBC padding side channel) from 2.14.0.

Summary

Botan is a BSD-licensed crypto library written in C++. It provides a

wide variety of basic cryptographic algorithms, X.509 certificates and

CRLs, PKCS \#10 certificate requests, a filter/pipe message processing

system, and a wide variety of other features, all written in portable

C++. The API reference, tutorial, and examples may help impart the

flavor of the library. This is the current stable release branch 2.x

of Botan.

Backport patch for #1849743 (CBC padding side channel) from 2.14.0.

* Sat Jul 4 2020 Thomas Moschny - 2.11.0-3

- Backport patch for #1849743 (CBC padding side channel) from 2.14.0

[ 1 ] Bug #1849745 - botan2: botan: CBC padding operations were not constant time and as a result would leak the length of the plaintext values which were being padded [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1849745

[ 2 ] Bug #1849746 - botan2: botan: CBC padding operations were not constant time and as a result would leak the length of the plaintext values which were being padded [epel-8]

https://bugzilla.redhat.com/show_bug.cgi?id=1849746

su -c 'dnf upgrade --advisory FEDORA-2020-f9a8f05df5' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Change Log

References

Update Instructions

Severity
important
Lowest
Low
Medium
High
Critical

Product: Fedora 31
Version: 2.11.0
Release: 3.fc31
Summary: Crypto and TLS for C++11

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here