CVE-2015-5727: High severity botan vulnerability
Published May 13, 2016
·Updated
The BER decoder in Botan 1.10.x before 1.10.10 and 1.11.x before 1.11.19 allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors, related to a length field.
Affected Software
30 affected components
Botan Project Botan=1.10.0
Botan Project Botan=1.10.1
Botan Project Botan=1.10.2
Botan Project Botan=1.10.3
Botan Project Botan=1.10.4
Botan Project Botan=1.10.5
Botan Project Botan=1.10.6
Botan Project Botan=1.10.7
Botan Project Botan=1.10.8
Botan Project Botan=1.10.9
Botan Project Botan=1.11.0
Botan Project Botan=1.11.1
Botan Project Botan=1.11.2
Botan Project Botan=1.11.3
Botan Project Botan=1.11.4
Botan Project Botan=1.11.5
Botan Project Botan=1.11.6
Botan Project Botan=1.11.7
Botan Project Botan=1.11.8
Botan Project Botan=1.11.9
Botan Project Botan=1.11.10
Botan Project Botan=1.11.11
Botan Project Botan=1.11.12
Botan Project Botan=1.11.13
Botan Project Botan=1.11.14
Botan Project Botan=1.11.15
Botan Project Botan=1.11.16
Botan Project Botan=1.11.17
Botan Project Botan=1.11.18
Debian Debian Linux=8.0
Event History
May 13, 2016
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-5727?
CVE-2015-5727 has a moderate severity as it allows remote attackers to cause denial of service through memory consumption.
2
How do I fix CVE-2015-5727?
To fix CVE-2015-5727, you should update Botan to version 1.10.10 or 1.11.19 or later.
3
Which versions of Botan are affected by CVE-2015-5727?
CVE-2015-5727 affects Botan versions 1.10.x before 1.10.10 and 1.11.x before 1.11.19.
4
Can CVE-2015-5727 be exploited remotely?
Yes, CVE-2015-5727 can be exploited remotely by attackers to cause a denial of service.
5
What type of attack does CVE-2015-5727 relate to?
CVE-2015-5727 relates to a denial of service attack due to excessive memory consumption.