Logo
vulnerabilityCVE-2024-34702
Name
CVE-2024-34702
Source
NVD ( link)Debian ( link)
Description
Botan is a C++ cryptography library. X.509 certificates can identify elliptic curves using either an object identifier or using explicit encoding of the parameters. Prior to 3.5.0 and 2.19.5, checking name constraints in X.509 certificates is quadratic in the number of names and name constraints. An attacker who presented a certificate chain which contained a very large number of names in the SubjectAlternativeName, signed by a CA certificate which contained a large number of name constraints, could cause a denial of service. The problem has been addressed in Botan 3.5.0 and a partial backport has also been applied and is included in Botan 2.19.5.
Published Date
Updated Date
Workaround
-
Advisories

Analysis#


Affected Component
Analysis
botan
Patched

Vulnerability Ratings#


5.3
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
3.5.0
Not Affected
buildroot
master
3.5.0
Not Affected
yocto
master
3.12.0
Not Affected
yocto
scarthgap
3.2.0
Not Affected

Resolved with patches#


botan (yocto:kirkstone)

#
Title
Author
Resolve
1
Address various name constraint bugs
Jack Lloyd <jack@randombit.net>
CVE-2024-34702
CVE-2024-39312