CVE-2016-2849: Infoleak
Botan before 1.10.13 and 1.11.x before 1.11.29 do not use a constant-time algorithm to perform a modular inverse on the signature nonce k, which might allow remote attackers to obtain ECDSA secret keys via a timing side-channel attack.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-2849?
CVE-2016-2849 has a high severity rating due to its potential for enabling remote attackers to exploit timing side-channel vulnerabilities.
Which software versions are affected by CVE-2016-2849?
CVE-2016-2849 affects Botan versions prior to 1.10.13 and versions in the 1.11.x series before 1.11.29.
How do I fix CVE-2016-2849?
To fix CVE-2016-2849, update Botan to version 1.10.13 or 1.11.29 or later.
What type of attack does CVE-2016-2849 allow?
CVE-2016-2849 allows remote attackers to perform a timing side-channel attack potentially leading to exposure of ECDSA secret keys.
Is CVE-2016-2849 a local or remote vulnerability?
CVE-2016-2849 is classified as a remote vulnerability, as it can be exploited by attackers over a network.