CVE-2015-7827

Priority
Description
Botan before 1.10.13 and 1.11.x before 1.11.22 make it easier for remote
attackers to conduct million-message attacks by measuring time differences,
related to decoding of PKCS#1 padding.
Notes
 sarnold> "Fixed in 1.11.22. Affected all previous versions."
Package
Upstream:released (1.10.13-1)
Ubuntu 12.04 ESM (Precise Pangolin):DNE (precise was needed)
Ubuntu 14.04 ESM (Trusty Tahr):DNE (trusty was released [1.10.5-1+deb7u1ubuntu0.14.04.1])
Ubuntu 16.04 LTS (Xenial Xerus):needed
Ubuntu 18.04 LTS (Bionic Beaver):not-affected (1.10.13-1)
Ubuntu 19.04 (Disco Dingo):DNE
Ubuntu 19.10 (Eoan):DNE
More Information

Updated: 2019-09-19 14:19:35 UTC (commit d32ebc32606b9517c6fa7d65a15441e2a57a6de5)