CVE-2016-8871: Infoleak
Published Oct 28, 2016
·Updated
In Botan 1.11.29 through 1.11.32, RSA decryption with certain padding options had a detectable timing channel which could given sufficient queries be used to recover plaintext, aka an "OAEP side channel" attack.
Affected Software
4 affected components
Botan Project Botan=1.11.29
Botan Project Botan=1.11.30
Botan Project Botan=1.11.31
Botan Project Botan=1.11.32
Event History
Oct 28, 2016
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-8871?
CVE-2016-8871 has a medium severity level due to its potential for yielding plaintext through a timing attack.
2
How do I fix CVE-2016-8871?
To fix CVE-2016-8871, upgrade Botan to a version later than 1.11.32 where the timing channel vulnerability is resolved.
3
What versions of Botan are affected by CVE-2016-8871?
CVE-2016-8871 affects Botan versions 1.11.29 through 1.11.32.
4
What is the impact of exploiting CVE-2016-8871?
Exploiting CVE-2016-8871 could allow an attacker to recover plaintext from RSA decryption operations.
5
Is CVE-2016-8871 a common vulnerability?
CVE-2016-8871 is a specific vulnerability in the Botan library and is not as commonly reported as other widespread threats.