Description
Botan 2.5.0 through 2.6.0 before 2.7.0 allows a memory-cache side-channel attack on ECDSA signatures, aka the Return Of the Hidden Number Problem or ROHNP, related to dsa/dsa.cpp, ec_group/ec_group.cpp, and ecdsa/ecdsa.cpp. To discover an ECDSA key, the attacker needs access to either the local machine or a different virtual machine on the same physical host.
References (3)
Core 3
Core References
Exploit, Third Party Advisory x_refsource_misc
https://www.nccgroup.trust/us/our-research/technical-advisory-return-of-the-hidden-number-problem/
Third Party Advisory x_refsource_confirm
https://botan.randombit.net/security.html
Patch, Third Party Advisory x_refsource_confirm
https://github.com/randombit/botan/commit/48fc8df51d99f9d8ba251219367b3d629cc848e3
Scores
CVSS v3
5.9
EPSS
0.0015
EPSS Percentile
35.6%
Attack Vector
LOCAL
CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N
Details
CWE
CWE-200
Status
published
Products (1)
botan_project/botan
2.5.0 - 2.7.0
Published
Jun 15, 2018
Tracked Since
Feb 18, 2026