Bugzilla – Bug 1121389
VUL-1: CVE-2018-20187: Botan: Side channel possible during ECC generation
Last modified: 2024-05-07 09:25:16 UTC
It was found that a possible Timing side channel during ECC key generation could leak information. Upstream PR: https://github.com/randombit/botan/pull/1792 Upstream patch: https://github.com/randombit/botan/pull/1792/commits/70aa7303acfff9eefc24598c289a84db3579ebd1 References: https://bugzilla.redhat.com/show_bug.cgi?id=1664598 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-20187
The vulnerable code was only introduced with 1.11.20, so no SLE codestreams are affected by this. openSUSE codestreams are affected, though.
All done, closing.