CVE-2014-9742
high
CVSS v3
7.5
CVSS v2
5.0
VIR risk
7.5
Description
The Miller-Rabin primality check in Botan before 1.10.8 and 1.11.x before 1.11.9 improperly uses a single random base, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via a DH group.
Predictions
Exploit likelihood
83%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: cve@mitre.org — http://marc.info/?l=botan-devel&m=139717503205066&w=2
Vendor advisory: cve@mitre.org — http://botan.randombit.net/security.html
Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2014-9742.html
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| sles | affected | |
Application impact
References
CWEs
CWE-310
Verify integrity in audit chain (admin only). AS-IS.