CVE-2015-7827: Infoleak
Published May 13, 2016
·Updated
Botan before 1.10.13 and 1.11.x before 1.11.22 make it easier for remote attackers to conduct million-message attacks by measuring time differences, related to decoding of PKCS#1 padding.
Affected Software
25 affected components
Fedoraproject Fedora=24
Botan Project Botan<=1.10.13
Botan Project Botan=1.11.0
Botan Project Botan=1.11.1
Botan Project Botan=1.11.2
Botan Project Botan=1.11.3
Botan Project Botan=1.11.4
Botan Project Botan=1.11.5
Botan Project Botan=1.11.6
Botan Project Botan=1.11.7
Botan Project Botan=1.11.8
Botan Project Botan=1.11.9
Botan Project Botan=1.11.10
Botan Project Botan=1.11.11
Botan Project Botan=1.11.12
Botan Project Botan=1.11.13
Botan Project Botan=1.11.14
Botan Project Botan=1.11.15
Botan Project Botan=1.11.16
Botan Project Botan=1.11.17
Botan Project Botan=1.11.18
Botan Project Botan=1.11.19
Botan Project Botan=1.11.20
Botan Project Botan=1.11.21
Debian Debian Linux=8.0
Event History
May 13, 2016
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-7827?
CVE-2015-7827 is classified as a medium severity vulnerability that can facilitate million-message attacks.
2
How do I fix CVE-2015-7827?
To resolve CVE-2015-7827, upgrade to Botan version 1.10.14 or 1.11.22 or later.
3
What impact does CVE-2015-7827 have on affected systems?
CVE-2015-7827 can lead to timing attacks that potentially allow remote attackers to manipulate PKCS#1 padding.
4
Which versions of Botan are affected by CVE-2015-7827?
Versions of Botan before 1.10.14 and 1.11.x before 1.11.22 are affected by CVE-2015-7827.
5
Is Fedora version 24 impacted by CVE-2015-7827?
Yes, Fedora version 24 is impacted by CVE-2015-7827 due to its use of Botan prior to the patched versions.