CVE-2017-14737: Medium severity botan vulnerability
A cryptographic cache-based side channel in the RSA implementation in Botan before 1.10.17, and 1.11.x and 2.x before 2.3.0, allows a local attacker to recover information about RSA secret keys, as demonstrated by CacheD. This occurs because an array is indexed with bits derived from a secret key.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-14737?
The severity of CVE-2017-14737 is categorized as high, as it allows local attackers to recover information about RSA secret keys.
How do I fix CVE-2017-14737?
To fix CVE-2017-14737, update Botan to version 1.10.17 or later, or to versions 2.3.0 or later.
What software is affected by CVE-2017-14737?
CVE-2017-14737 affects Botan versions before 1.10.17 and all 1.11.x and 2.x versions prior to 2.3.0.
Who is impacted by CVE-2017-14737?
Local attackers are impacted by CVE-2017-14737 as they can exploit the vulnerability to extract RSA secret keys.
What type of vulnerability is CVE-2017-14737?
CVE-2017-14737 is a cryptographic cache-based side channel vulnerability specifically within the RSA implementation in Botan.