CVE-2016-2849

Priority
Description
Botan before 1.10.13 and 1.11.x before 1.11.29 do not use a constant-time
algorithm to perform a modular inverse on the signature nonce k, which
might allow remote attackers to obtain ECDSA secret keys via a timing
side-channel attack.
Notes
Package
Upstream:released (1.10.13-1)
Ubuntu 12.04 ESM (Precise Pangolin):DNE (precise was needed)
Ubuntu 14.04 ESM (Trusty Tahr):DNE (trusty was released [1.10.5-1+deb7u1ubuntu0.14.04.1])
Ubuntu 16.04 LTS (Xenial Xerus):needed
Ubuntu 18.04 LTS (Bionic Beaver):not-affected (1.10.13-1)
Ubuntu 19.10 (Eoan Ermine):DNE
Ubuntu 20.04 (Focal Fossa):DNE
More Information

Updated: 2020-04-24 03:27:57 UTC (commit d3f8a6ed481830fb100109a132bef581fc4176fe)