CVE-2017-7252: High severity botan vulnerability
Published Nov 3, 2023
·Updated
bcrypt password hashing in Botan before 2.1.0 does not correctly handle passwords with a length between 57 and 72 characters, which makes it easier for attackers to determine the cleartext password.
Affected Software
1 affected component
Botan Project Botan>=1.11.0<2.1.0
Event History
Nov 3, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2017-7252.
2
What is the severity of CVE-2017-7252?
CVE-2017-7252 has a severity level of 7.5 (high).
3
How does the vulnerability in Botan affect the password hashing?
The vulnerability in Botan affects the bcrypt password hashing, specifically passwords with a length between 57 and 72 characters.
4
What is the impact of this vulnerability?
The vulnerability makes it easier for attackers to determine the cleartext password.
5
Is there a fix available for CVE-2017-7252?
Yes, the fix is available in Botan version 2.1.0.