Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Botan 1.11.x before 1.11.29 does not enforce TLS policy for (1) signature algorithms and (2) ECC curves, which allows remote attackers to conduct downgrade attacks via unspecified vectors.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Botan 安全漏洞
Vulnerability Description
Botan是一款使用C++编写的加密算法库,它支持AES、DES、SHA-1、RSA、DSA和Diffie-Hellman等多种算法。 Botan 1.11.29之前1.11.x版本中存在安全漏洞,该漏洞源于程序没有对签名算法和ECC椭圆曲线算法强制执行TLS策略。远程攻击者可利用该漏洞实施降级攻击。
CVSS Information
N/A
Vulnerability Type
N/A