Bug 965621 (CVE-2016-2194) - VUL-0: CVE-2016-2194: botan: various flaws fixed in 1.11.27 and 1.10.11
Summary: VUL-0: CVE-2016-2194: botan: various flaws fixed in 1.11.27 and 1.10.11
Status: RESOLVED FIXED
Alias: CVE-2016-2194
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/161644/
Whiteboard: CVSSv2:RedHat:CVE-2016-2194:6.8:(AV:N...
Keywords:
Depends on:
Blocks:
 
Reported: 2016-02-08 13:30 UTC by Sebastian Krahmer
Modified: 2017-10-06 14:37 UTC (History)
4 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sebastian Krahmer 2016-02-08 13:30:14 UTC
Quoting from RH:

"2016-02-01 (CVE-2016-2194): Infinite loop in modulur square root algorithm

The ressol function implements the Tonelli-Shanks algorithm for finding square roots could be sent into a nearly infinite loop due to a misplaced conditional check. This could occur if a composite modulus is provided, as this algorithm is only defined for primes. This function is exposed to attacker controlled input via the OS2ECP function during ECC point decompression. Found by AFL

Introduced in 1.7.15, fixed in 1.11.27 and 1.10.11

External References:

http://botan.randombit.net/security.html#id1

"

References:
https://bugzilla.redhat.com/show_bug.cgi?id=1305439
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-2195
Comment 1 Bernhard Wiedemann 2017-04-12 16:02:07 UTC
This is an autogenerated message for OBS integration:
This bug (965621) was mentioned in
https://build.opensuse.org/request/show/487622 Factory / Botan
Comment 5 Daniel Molkentin 2017-04-24 09:42:41 UTC
SLE12 submitted, SLE 11 unaffected, back to security team for processing.
Comment 6 Swamp Workflow Management 2017-05-09 16:11:03 UTC
SUSE-SU-2017:1222-1: An update that fixes 9 vulnerabilities is now available.

Category: security (moderate)
Bug References: 1013209,1033605,965620,965621,968025,968026,968030,974521,977420
CVE References: CVE-2014-9742,CVE-2015-5726,CVE-2015-5727,CVE-2015-7827,CVE-2016-2194,CVE-2016-2195,CVE-2016-2849,CVE-2016-9132,CVE-2017-2801
Sources used:
SUSE Linux Enterprise Software Development Kit 12-SP2 (src):    Botan-1.10.9-3.1
SUSE Linux Enterprise Software Development Kit 12-SP1 (src):    Botan-1.10.9-3.1
Comment 7 Marcus Meissner 2017-06-20 11:38:51 UTC
released