CVE-2018-20187
5.9
MEDIUM
CVSS 3.1
EPSS 1.5%
描述
A side-channel issue was discovered in Botan before 2.9.0. An attacker capable of precisely measuring the time taken for ECC key generation may be able to derive information about the high bits of the secret key, as the function to derive the public point from the secret scalar uses an unblinded Montgomery ladder whose loop iteration count depends on the bitlength of the secret. This issue affects only key generation, not ECDSA signatures or ECDH key agreement.
如何修補 CVE-2018-20187
要修補 CVE-2018-20187,請將受影響套件升級到下列已修補版本。
- —升級至 2.9.0-r0 或更新版本
- —升級至 2.9.0-2 或更新版本
CVE-2018-20187 正在被利用嗎?
低 — EPSS 為 1.5%,目前沒有觀察到大規模利用活動。
受影響套件(2)
- from 0, < 2.9.0-r0
- from 0, < 2.9.0-2
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.9 | CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N |