CVE-2018-20187
Summary
| CVE | CVE-2018-20187 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-03-08 19:29:00 UTC |
| Updated | 2019-03-12 20:39:00 UTC |
| Description | A side-channel issue was discovered in Botan before 2.9.0. An attacker capable of precisely measuring the time taken for ECC key generation may be able to derive information about the high bits of the secret key, as the function to derive the public point from the secret scalar uses an unblinded Montgomery ladder whose loop iteration count depends on the bitlength of the secret. This issue affects only key generation, not ECDSA signatures or ECDH key agreement. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Security Advisories — Botan |
MISC |
botan.randombit.net |
Vendor Advisory |
| GitHub - crocs-muni/ECTester: Tests support and behavior of elliptic curve cryptography implementations on JavaCards (TYPE_EC_FP and TYPE_EC_F2M) and in selected software libraries. |
MISC |
github.com |
Not Applicable, Third Party Advisory |
| Release Notes — Botan |
MISC |
botan.randombit.net |
Release Notes, Vendor Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 500074 Alpine Linux Security Update for botan
- 503750 Alpine Linux Security Update for botan
- 690251 Free Berkeley Software Distribution (FreeBSD) Security Update for botan2 (d8e7e854-17fa-11e9-bef6-6805ca2fa271)