CVE-2016-2195
Severity CVSS v4.0:
Pending analysis
Type:
CWE-119
Buffer Errors
Publication date:
13/05/2016
Last modified:
12/04/2025
Description
Integer overflow in the PointGFp constructor in Botan before 1.10.11 and 1.11.x before 1.11.27 allows remote attackers to overwrite memory and possibly execute arbitrary code via a crafted ECC point, which triggers a heap-based buffer overflow.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Base Score 2.0
10.00
Severity 2.0
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:botan_project:botan:*:*:*:*:*:*:*:* | 1.10.10 (including) | |
cpe:2.3:a:botan_project:botan:1.11.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:botan_project:botan:1.11.1:*:*:*:*:*:*:* | ||
cpe:2.3:a:botan_project:botan:1.11.2:*:*:*:*:*:*:* | ||
cpe:2.3:a:botan_project:botan:1.11.3:*:*:*:*:*:*:* | ||
cpe:2.3:a:botan_project:botan:1.11.4:*:*:*:*:*:*:* | ||
cpe:2.3:a:botan_project:botan:1.11.5:*:*:*:*:*:*:* | ||
cpe:2.3:a:botan_project:botan:1.11.6:*:*:*:*:*:*:* | ||
cpe:2.3:a:botan_project:botan:1.11.7:*:*:*:*:*:*:* | ||
cpe:2.3:a:botan_project:botan:1.11.8:*:*:*:*:*:*:* | ||
cpe:2.3:a:botan_project:botan:1.11.9:*:*:*:*:*:*:* | ||
cpe:2.3:a:botan_project:botan:1.11.10:*:*:*:*:*:*:* | ||
cpe:2.3:a:botan_project:botan:1.11.11:*:*:*:*:*:*:* | ||
cpe:2.3:a:botan_project:botan:1.11.12:*:*:*:*:*:*:* | ||
cpe:2.3:a:botan_project:botan:1.11.13:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://botan.randombit.net/security.html
- http://marc.info/?l=botan-devel&m=145435148602911&w=2
- http://www.debian.org/security/2016/dsa-3565
- https://security.gentoo.org/glsa/201612-38
- http://botan.randombit.net/security.html
- http://marc.info/?l=botan-devel&m=145435148602911&w=2
- http://www.debian.org/security/2016/dsa-3565
- https://security.gentoo.org/glsa/201612-38