CVE-2016-6879: High severity botan vulnerability
Published Apr 10, 2017
·Updated
The X509Certificate::allowedusage function in botan 1.11.x before 1.11.31 might allow attackers to have unspecified impact by leveraging a call with more than one KeyUsage set in the enum value.
Affected Software
31 affected components
Botan Project Botan=1.11.0
Botan Project Botan=1.11.1
Botan Project Botan=1.11.2
Botan Project Botan=1.11.3
Botan Project Botan=1.11.4
Botan Project Botan=1.11.5
Botan Project Botan=1.11.6
Botan Project Botan=1.11.7
Botan Project Botan=1.11.8
Botan Project Botan=1.11.9
Botan Project Botan=1.11.10
Botan Project Botan=1.11.11
Botan Project Botan=1.11.12
Botan Project Botan=1.11.13
Botan Project Botan=1.11.14
Botan Project Botan=1.11.15
Botan Project Botan=1.11.16
Botan Project Botan=1.11.17
Botan Project Botan=1.11.18
Botan Project Botan=1.11.19
Botan Project Botan=1.11.20
Botan Project Botan=1.11.21
Botan Project Botan=1.11.22
Botan Project Botan=1.11.23
Botan Project Botan=1.11.24
Botan Project Botan=1.11.25
Botan Project Botan=1.11.26
Botan Project Botan=1.11.27
Botan Project Botan=1.11.28
Botan Project Botan=1.11.29
Botan Project Botan=1.11.30
Event History
Apr 10, 2017
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-6879?
CVE-2016-6879 is classified as having an unspecified severity that allows attackers to potentially exploit the vulnerability.
2
How do I fix CVE-2016-6879?
To fix CVE-2016-6879, upgrade to Botan version 1.11.31 or later.
3
What versions of Botan are affected by CVE-2016-6879?
CVE-2016-6879 affects Botan versions 1.11.0 through 1.11.30.
4
What type of vulnerability is CVE-2016-6879?
CVE-2016-6879 is a vulnerability related to improper handling of Key_Usage in X.509 certificates.
5
Who is affected by CVE-2016-6879?
Any organization using Botan versions 1.11.0 to 1.11.30 for cryptographic operations may be affected by CVE-2016-6879.