Bug 1033435 - (CVE-2016-6879) VUL-0: CVE-2016-6879: Botan: The X509_Certificate::allowed_usage function security issue
(CVE-2016-6879)
VUL-0: CVE-2016-6879: Botan: The X509_Certificate::allowed_usage function sec...
Status: RESOLVED INVALID
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P5 - None : Normal
: ---
Assigned To: Daniel Molkentin
Security Team bot
https://smash.suse.de/issue/183340/
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2017-04-11 05:53 UTC by Victor Pereira
Modified: 2017-04-11 15:38 UTC (History)
3 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Victor Pereira 2017-04-11 05:53:33 UTC
CVE-2016-6879

The X509_Certificate::allowed_usage function in botan 1.11.x before 1.11.31
might allow attackers to have unspecified impact by leveraging a call with more
than one Key_Usage set in the enum value.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-6879
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-6879
Comment 1 Nicolas Morey-Chaisemartin 2017-04-11 07:36:25 UTC
As this only impacts the 1.11.x branch while we are based on the 1.10.x branch, I don't think we are concerned by this bug
Comment 2 Daniel Molkentin 2017-04-11 12:26:06 UTC
Agreed. Closing.