Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Integer overflow in the PointGFp constructor in Botan before 1.10.11 and 1.11.x before 1.11.27 allows remote attackers to overwrite memory and possibly execute arbitrary code via a crafted ECC point, which triggers a heap-based buffer overflow.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Botan 整数溢出漏洞
Vulnerability Description
Botan是一款使用C++编写的加密算法库,它支持AES、DES、SHA-1、RSA、DSA和Diffie-Hellman等多种算法。 Botan 1.10.11之前版本和1.11.27之前1.11.x版本的PointGFp构造函数中存在整数溢出漏洞。远程攻击者可借助特制的ECC端点利用该漏洞覆盖内存,执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A