"Botan 2.19.3 has been released today fixing a security issue when verifying OCSP responses. It is possible for a malicious responder to falsify a OCSP response - notably this vulnerability also affects stapled OCSP responses in TLS."
The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=9841574e46260f409c25aea7c4b7a95bc1aad1d4 commit 9841574e46260f409c25aea7c4b7a95bc1aad1d4 Author: Sam James <sam@gentoo.org> AuthorDate: 2022-11-17 01:01:46 +0000 Commit: Sam James <sam@gentoo.org> CommitDate: 2022-11-17 01:01:46 +0000 dev-libs/botan: add 2.19.3 Bug: https://bugs.gentoo.org/881529 Signed-off-by: Sam James <sam@gentoo.org> dev-libs/botan/Manifest | 2 + dev-libs/botan/botan-2.19.3.ebuild | 180 +++++++++++++++++++++++++++++++++++++ 2 files changed, 182 insertions(+)