Sicherheit: Zwei Probleme in botan2
Name: Zwei Probleme in botan2
ID: FEDORA-2018-98ab6b4e56
Distribution: Fedora
Plattformen: Fedora 27
Datum: Mi, 11. Juli 2018, 22:51
Referenzen: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-0495
Applikationen: botan


Fedora Update Notification
2018-07-11 19:27:57.419836

Name : botan2
Product : Fedora 27
Version : 2.7.0
Release : 1.fc27
URL : https://botan.randombit.net/
Summary : Crypto and TLS for C++11
Description :
Botan is a BSD-licensed crypto library written in C++. It provides a
wide variety of basic cryptographic algorithms, X.509 certificates and
CRLs, PKCS \#10 certificate requests, a filter/pipe message processing
system, and a wide variety of other features, all written in portable
C++. The API reference, tutorial, and examples may help impart the
flavor of the library. This is the current stable release branch 2.x
of Botan.

Update Information:

Update Botan2 to 2.7.0. Focus of this release is on performance and side
channel hardening. - Address side channels in RSA key generation and ECDSA
signing - Side channel hardening in many core algorithms (modular
exponentiation, ECC scalar multiply, Karatsuba multiplication, Barrett
reduction, etc) to reduce the risk of future exploitable side channels. - Many
optimizations for ECC operations, RSA (including key gen), DSA, DH, and XMSS.
Typical speedups vs 2.6.0 is 10 to 40% depending on operation and key size. -
Add Scrypt password hashing. Also supported is using Scrypt to derive keys for
private key encryption (format compatible with upcoming OpenSSL 1.1.1) - Add
base32 encoding/decoding - Plus many bug fixes and smaller enhancements
documented in the [release

[ 1 ] Bug #1591831 - CVE-2018-12435 botan: memory-cache side-channel attack
on ECDSA signatures
[ 2 ] Bug #1591163 - CVE-2018-0495 openssl: ROHNP - Key Extraction Side
Channel in Multiple Crypto Libraries

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2018-98ab6b4e56' at the command
line. For more information, refer to the dnf documentation available at

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
