Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 632104 (CVE-2017-14737) - <dev-libs/botan-1.10.17: cryptographic cache-based side channel in the RSA implementation
Summary: <dev-libs/botan-1.10.17: cryptographic cache-based side channel in the RSA im...
Status: RESOLVED FIXED
Alias: CVE-2017-14737
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Low minor (vote)
Assignee: Gentoo Security
URL: https://github.com/randombit/botan/is...
Whiteboard: B4 [noglsa cve]
Keywords:
Depends on:
Blocks:
 
Reported: 2017-09-26 20:32 UTC by Aleksandr Wagner (Kivak)
Modified: 2017-10-13 23:15 UTC (History)
4 users (show)

See Also:
Package list:
=dev-libs/botan-1.10.17 amd64 hppa ppc ppc64 x86
Runtime testing required: ---
stable-bot: sanity-check+


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Aleksandr Wagner (Kivak) 2017-09-26 20:32:23 UTC
CVE-2017-14737 (http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-14737):

A cryptographic cache-based side channel in the RSA implementation in Botan before 1.10.17, and 1.11.x and 2.x before 2.3.0, allows a local attacker to recover information about RSA secret keys, as demonstrated by CacheD. This occurs because an array is indexed with bits derived from a secret key. 

References:

https://github.com/randombit/botan/issues/1222
https://www.usenix.org/conference/usenixsecurity17/technical-sessions/presentation/wang-shuai
https://github.com/randombit/botan/pull/1224
Comment 1 Alon Bar-Lev gentoo-dev 2017-10-04 06:23:03 UTC
Added, please stabilize.
Comment 2 Sergei Trofimovich gentoo-dev 2017-10-04 08:53:19 UTC
ppc64 stable
Comment 3 Thomas Deutschmann gentoo-dev Security 2017-10-04 22:54:07 UTC
x86 stable
Comment 4 Sergei Trofimovich gentoo-dev 2017-10-05 08:42:51 UTC
ppc stable
Comment 5 Sergei Trofimovich gentoo-dev 2017-10-10 11:40:14 UTC
hppa stable
Comment 6 Manuel Rüger (RETIRED) gentoo-dev 2017-10-11 18:28:20 UTC
amd64 stable
Comment 7 Aleksandr Wagner (Kivak) 2017-10-12 13:42:01 UTC
Stabilization is done, thank you arches.

@Maintainer(s): Please clean the vulnerable versions from tree.

Gentoo Security Padawan
Kivak
Comment 8 Alon Bar-Lev gentoo-dev 2017-10-12 16:40:38 UTC
(In reply to Aleksandr Wagner (Kivak) from comment #7)
> @Maintainer(s): Please clean the vulnerable versions from tree.

Done.
Comment 9 Aaron Bauman Gentoo Infrastructure gentoo-dev Security 2017-10-13 23:15:24 UTC
GLSA Vote: No