Ubuntu alert USN-7586-1 (botan)
| From: | noreply+usn-bot@canonical.com | |
| To: | ubuntu-security-announce@lists.ubuntu.com | |
| Subject: | [USN-7586-1] Botan vulnerabilities | |
| Date: | Mon, 23 Jun 2025 05:19:46 +0000 | |
| Message-ID: | <E1uTZas-0007pL-Bh@lists.ubuntu.com> |
========================================================================== Ubuntu Security Notice USN-7586-1 June 23, 2025 botan vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: Several security issues were fixed in Botan. Software Description: - botan: C++ cryptography library Details: It was discovered that Botan could have compiler dependent operations induced under certain circumstances. An attacker could possibly use this issue to cause undefined behavior. (CVE-2024-50382, CVE-2024-50383) Bing Shi discovered that Botan did not limit the size of certain inputs when checking primality and name constraints. An attacker could possibly use this issue to cause a denial of service. (CVE-2024-34702, CVE-2024-34703) It was discovered that Botan did not correctly handle conflicting name constraints. An attacker could possibly use this issue to bypass authentication. (CVE-2024-39312) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.10 botan 2.19.3+dfsg-1ubuntu2.1 libbotan-2-19 2.19.3+dfsg-1ubuntu2.1 libbotan-2-dev 2.19.3+dfsg-1ubuntu2.1 python3-botan 2.19.3+dfsg-1ubuntu2.1 Ubuntu 24.04 LTS botan 2.19.3+dfsg-1ubuntu2+esm1 Available with Ubuntu Pro libbotan-2-19 2.19.3+dfsg-1ubuntu2+esm1 Available with Ubuntu Pro libbotan-2-dev 2.19.3+dfsg-1ubuntu2+esm1 Available with Ubuntu Pro python3-botan 2.19.3+dfsg-1ubuntu2+esm1 Available with Ubuntu Pro Ubuntu 22.04 LTS botan 2.19.1+dfsg-2ubuntu1+esm1 Available with Ubuntu Pro libbotan-2-19 2.19.1+dfsg-2ubuntu1+esm1 Available with Ubuntu Pro libbotan-2-dev 2.19.1+dfsg-2ubuntu1+esm1 Available with Ubuntu Pro python3-botan 2.19.1+dfsg-2ubuntu1+esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7586-1 CVE-2024-34702, CVE-2024-34703, CVE-2024-39312, CVE-2024-50382, CVE-2024-50383 Package Information: https://launchpad.net/ubuntu/+source/botan/2.19.3+dfsg-1u...
Attachment: signature.asc (type=application/pgp-signature)
-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmhY41wACgkQcpJm3tlz hgHr8BAA1k785uuB9Dront1kxKICKj5FrwQt64HoElsJA4SBg+oEOL59CKubvs1s Bc1bg5yUFA+zpjUwg3akqf5p2hUXrLspE6nZmGvw3SAsvexIe1JgOhMOWoLV1TaW t26yFbeinVpi3iQpNUk7A698n4ogoeXuyB6zyqtLuoH9iDGkmLhOjagsQqtNJs6F N+coX5aB6u3l+CAkymzKwU6+drVIIn5h9Hd+cmsaelgrypK37c/OItbjVHiVQkmy dbBJq2HAD6/a7q+QiLfGuFWeVEnm/LfjX/dlmSxQxziO1027KGKQ25pMWnpPxfE5 dE7ua6wl7fvt4xjUf/Fn3sIj84vh5fCRn5u+JIzOtDLWzz5Qi8dktFCZluM9t8kp r4ARj1rbKZknno+I4jAe01M5bC3zDWn8KiMB1ixFIQ7OA2dsoND7+WwBDsAOhUup 7eF8eE+tUJralFt6OMtQab/MZ1FF56CgL9Rze7Vw8bl2J7310gqGlDM6rQRI/NUw IE6/fkmEXaw9xHjFM/ZuMYkUPURwarj3nQsBGIzm6i3EzBhGbW7kIMnFjzrzXMM2 ja/POOGQSZUzNiBhM616oJJ/+flBON7+u+wwqthdypqp952kgiMSZpUKdMR4d4bw d+eSK7T3GBgKNrWPOEA0MOeemzBQzNqxJURDTahErA7cXypuAto= =npkB -----END PGP SIGNATURE-----
