UBUNTU-CVE-2021-24115

Source
https://ubuntu.com/security/CVE-2021-24115
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-24115.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2021-24115
Upstream
Published
2021-02-22T02:15:00Z
Modified
2025-07-16T08:15:33.929477Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
  • Ubuntu - low
Summary
[none]
Details

In Botan before 2.17.3, constant-time computations are not used for certain decoding and encoding operations (base32, base58, base64, and hex).

References

Affected packages

Ubuntu:Pro:14.04:LTS / botan1.10

Package

Name
botan1.10
Purl
pkg:deb/ubuntu/botan1.10@1.10.5-1+deb7u1ubuntu0.14.04.1+esm1?arch=source&distro=esm-infra-legacy/trusty

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.10.5-1
1.10.5-1ubuntu1
1.10.5-1+deb7u1ubuntu0.14.04.1
1.10.5-1+deb7u1ubuntu0.14.04.1+esm1

Ubuntu:Pro:16.04:LTS / botan1.10

Package

Name
botan1.10
Purl
pkg:deb/ubuntu/botan1.10@1.10.12-1?arch=source&distro=esm-apps/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.10.10-6
1.10.12-1

Ubuntu:Pro:18.04:LTS / botan

Package

Name
botan
Purl
pkg:deb/ubuntu/botan@2.4.0-5ubuntu1?arch=source&distro=esm-apps/bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*

2.4.0-3
2.4.0-4
2.4.0-5ubuntu1

Ubuntu:Pro:18.04:LTS / botan1.10

Package

Name
botan1.10
Purl
pkg:deb/ubuntu/botan1.10@1.10.17-0.1?arch=source&distro=esm-apps/bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.10.16-1
1.10.17-0.1

Ubuntu:Pro:20.04:LTS / botan

Package

Name
botan
Purl
pkg:deb/ubuntu/botan@2.12.1-2build1?arch=source&distro=esm-apps/focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*

2.9.0-2
2.9.0-2build1
2.12.1-2
2.12.1-2build1