CVE-2024-34702
5.3
MEDIUM
CVSS 3.1
EPSS 0.84%
描述
Botan is a C++ cryptography library. X.509 certificates can identify elliptic curves using either an object identifier or using explicit encoding of the parameters. Prior to 3.5.0 and 2.19.5, checking name constraints in X.509 certificates is quadratic in the number of names and name constraints. An attacker who presented a certificate chain which contained a very large number of names in the SubjectAlternativeName, signed by a CA certificate which contained a large number of name constraints, could cause a denial of service. The problem has been addressed in Botan 3.5.0 and a partial backport has also been applied and is included in Botan 2.19.5.
如何修補 CVE-2024-34702
要修補 CVE-2024-34702,請將受影響套件升級到下列已修補版本。
- —升級至 2.19.5-r0 或更新版本
- —升級至 3.5.0-r0 或更新版本
- —未列出修補版本
CVE-2024-34702 正在被利用嗎?
低 — EPSS 為 0.8%,目前沒有觀察到大規模利用活動。
受影響套件(3)
- from 0, < 2.19.5-r0
- from 0, < 3.5.0-r0
- from 0
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.3 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |