Your submission was sent successfully! Close

CVE-2016-2196

Published: 13 May 2016

Heap-based buffer overflow in the P-521 reduction function in Botan 1.11.x before 1.11.27 allows remote attackers to cause a denial of service (memory overwrite and crash) or execute arbitrary code via unspecified vectors.

Notes

AuthorNote
seth-arnold
"Introduced in 1.11.10, fixed in 1.11.27"
Priority

Medium

CVSS 3 base score: 9.8

Status

Package Release Status
botan1.10
Launchpad, Ubuntu, Debian
artful Not vulnerable
(1.10.16-1)
precise Does not exist
(precise was needed)
trusty Does not exist
(trusty was not-affected [1.10.5-1ubuntu1])
upstream
Released (1.11.27)
wily Ignored
(reached end-of-life)
xenial Not vulnerable
(1.10.12-1)
yakkety Ignored
(reached end-of-life)
zesty Ignored
(reached end-of-life)