CVE-2018-20187
5.9
MEDIUM
CVSS 3.1
EPSS 0.39%
Description
A side-channel issue was discovered in Botan before 2.9.0. An attacker capable of precisely measuring the time taken for ECC key generation may be able to derive information about the high bits of the secret key, as the function to derive the public point from the secret scalar uses an unblinded Montgomery ladder whose loop iteration count depends on the bitlength of the secret. This issue affects only key generation, not ECDSA signatures or ECDH key agreement.
How to fix CVE-2018-20187
To remediate CVE-2018-20187, upgrade the affected package to a fixed version below.
- —upgrade to 2.9.0-r0 or later
- —upgrade to 2.9.0-2 or later
Is CVE-2018-20187 being exploited?
Low — EPSS is 0.4%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 2.9.0-r0
- from 0, < 2.9.0-2
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.9 | CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N |