{"id":"CVE-2017-14737","details":"A cryptographic cache-based side channel in the RSA implementation in Botan before 1.10.17, and 1.11.x and 2.x before 2.3.0, allows a local attacker to recover information about RSA secret keys, as demonstrated by CacheD. This occurs because an array is indexed with bits derived from a secret key.","modified":"2026-07-07T08:49:23.799749386Z","published":"2017-09-26T01:29:03.303Z","related":["SUSE-SU-2017:2855-1","openSUSE-SU-2024:10594-1"],"database_specific":{"unresolved_ranges":[{"extracted_events":[{"introduced":"9.0"},{"last_affected":"9.0"}],"source":"CPE_STRING","vendor_product":"debian:debian_linux","cpes":["cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*"]}]},"references":[{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2021/11/msg00006.html"},{"type":"ADVISORY","url":"https://www.usenix.org/conference/usenixsecurity17/technical-sessions/presentation/wang-shuai"},{"type":"REPORT","url":"https://github.com/randombit/botan/issues/1222"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/randombit/botan","events":[{"introduced":"0"},{"last_affected":"3756c97d295d06ac19cec6736e05003afb10623e"},{"introduced":"ee912cd748a9b0bf56c84a49896dd2d57e0f81a6"},{"last_affected":"33f87a596ffa1fcbc017d9593dce0906d7d32208"}],"database_specific":{"cpe":["cpe:2.3:a:botan_project:botan:*:*:*:*:*:*:*:*","cpe:2.3:a:botan_project:botan:1.11.0:*:*:*:*:*:*:*","cpe:2.3:a:botan_project:botan:1.11.1:*:*:*:*:*:*:*","cpe:2.3:a:botan_project:botan:1.11.2:*:*:*:*:*:*:*","cpe:2.3:a:botan_project:botan:1.11.3:*:*:*:*:*:*:*","cpe:2.3:a:botan_project:botan:1.11.4:*:*:*:*:*:*:*","cpe:2.3:a:botan_project:botan:1.11.5:*:*:*:*:*:*:*","cpe:2.3:a:botan_project:botan:1.11.6:*:*:*:*:*:*:*","cpe:2.3:a:botan_project:botan:1.11.7:*:*:*:*:*:*:*","cpe:2.3:a:botan_project:botan:1.11.8:*:*:*:*:*:*:*","cpe:2.3:a:botan_project:botan:1.11.9:*:*:*:*:*:*:*","cpe:2.3:a:botan_project:botan:1.11.10:*:*:*:*:*:*:*","cpe:2.3:a:botan_project:botan:1.11.11:*:*:*:*:*:*:*","cpe:2.3:a:botan_project:botan:1.11.12:*:*:*:*:*:*:*","cpe:2.3:a:botan_project:botan:1.11.13:*:*:*:*:*:*:*","cpe:2.3:a:botan_project:botan:1.11.14:*:*:*:*:*:*:*","cpe:2.3:a:botan_project:botan:1.11.15:*:*:*:*:*:*:*","cpe:2.3:a:botan_project:botan:1.11.16:*:*:*:*:*:*:*","cpe:2.3:a:botan_project:botan:1.11.17:*:*:*:*:*:*:*","cpe:2.3:a:botan_project:botan:1.11.18:*:*:*:*:*:*:*","cpe:2.3:a:botan_project:botan:1.11.19:*:*:*:*:*:*:*","cpe:2.3:a:botan_project:botan:1.11.20:*:*:*:*:*:*:*","cpe:2.3:a:botan_project:botan:1.11.21:*:*:*:*:*:*:*","cpe:2.3:a:botan_project:botan:1.11.22:*:*:*:*:*:*:*","cpe:2.3:a:botan_project:botan:1.11.23:*:*:*:*:*:*:*","cpe:2.3:a:botan_project:botan:1.11.24:*:*:*:*:*:*:*","cpe:2.3:a:botan_project:botan:1.11.25:*:*:*:*:*:*:*","cpe:2.3:a:botan_project:botan:1.11.26:*:*:*:*:*:*:*","cpe:2.3:a:botan_project:botan:1.11.27:*:*:*:*:*:*:*","cpe:2.3:a:botan_project:botan:1.11.28:*:*:*:*:*:*:*","cpe:2.3:a:botan_project:botan:1.11.33:*:*:*:*:*:*:*","cpe:2.3:a:botan_project:botan:1.11.34:*:*:*:*:*:*:*","cpe:2.3:a:botan_project:botan:2.0.0:*:*:*:*:*:*:*","cpe:2.3:a:botan_project:botan:2.0.1:*:*:*:*:*:*:*","cpe:2.3:a:botan_project:botan:2.1.0:*:*:*:*:*:*:*","cpe:2.3:a:botan_project:botan:2.2.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"0"},{"last_affected":"1.10.16"},{"introduced":"1.11.0"},{"last_affected":"1.11.0"},{"introduced":"1.11.1"},{"last_affected":"1.11.1"},{"introduced":"1.11.2"},{"last_affected":"1.11.2"},{"introduced":"1.11.3"},{"last_affected":"1.11.3"},{"introduced":"1.11.4"},{"last_affected":"1.11.4"},{"introduced":"1.11.5"},{"last_affected":"1.11.5"},{"introduced":"1.11.6"},{"last_affected":"1.11.6"},{"introduced":"1.11.7"},{"last_affected":"1.11.7"},{"introduced":"1.11.8"},{"last_affected":"1.11.8"},{"introduced":"1.11.9"},{"last_affected":"1.11.9"},{"introduced":"1.11.10"},{"last_affected":"1.11.10"},{"introduced":"1.11.11"},{"last_affected":"1.11.11"},{"introduced":"1.11.12"},{"last_affected":"1.11.12"},{"introduced":"1.11.13"},{"last_affected":"1.11.13"},{"introduced":"1.11.14"},{"last_affected":"1.11.14"},{"introduced":"1.11.15"},{"last_affected":"1.11.15"},{"introduced":"1.11.16"},{"last_affected":"1.11.16"},{"introduced":"1.11.17"},{"last_affected":"1.11.17"},{"introduced":"1.11.18"},{"last_affected":"1.11.18"},{"introduced":"1.11.19"},{"last_affected":"1.11.19"},{"introduced":"1.11.20"},{"last_affected":"1.11.20"},{"introduced":"1.11.21"},{"last_affected":"1.11.21"},{"introduced":"1.11.22"},{"last_affected":"1.11.22"},{"introduced":"1.11.23"},{"last_affected":"1.11.23"},{"introduced":"1.11.24"},{"last_affected":"1.11.24"},{"introduced":"1.11.25"},{"last_affected":"1.11.25"},{"introduced":"1.11.26"},{"last_affected":"1.11.26"},{"introduced":"1.11.27"},{"last_affected":"1.11.27"},{"introduced":"1.11.28"},{"last_affected":"1.11.28"},{"introduced":"1.11.33"},{"last_affected":"1.11.33"},{"introduced":"1.11.34"},{"last_affected":"1.11.34"},{"introduced":"2.0.0"},{"last_affected":"2.0.0"},{"introduced":"2.0.1"},{"last_affected":"2.0.1"},{"introduced":"2.1.0"},{"last_affected":"2.1.0"},{"introduced":"2.2.0"},{"last_affected":"2.2.0"}],"source":["CPE_RANGE","CPE_STRING"]}}],"versions":["1.11.0","1.11.1","1.11.10","1.11.11","1.11.12","1.11.13","1.11.14","1.11.15","1.11.16","1.11.17","1.11.18","1.11.19","1.11.2","1.11.20","1.11.21","1.11.22","1.11.23","1.11.24","1.11.25","1.11.26","1.11.27","1.11.28","1.11.3","1.11.33","1.11.34","1.11.4","1.11.5","1.11.6","1.11.7","1.11.8","1.11.9","2.0.0","2.0.1","2.1.0","2.2.0","1.10.16","1.10.15","1.10.14","1.10.13","1.11.32","1.11.31","1.11.30","1.11.29","1.10.12","1.10.11","1.10.9","1.10.8","1.10.6","1.10.5","1.10.3","1.10.2","1.10.1","1.10.0","1.9.18","1.9.17","1.9.16","1.9.15","1.10.0-rc1","1.9.14","1.9.13","1.9.12","1.9.11","1.9.10","1.9.9","1.9.8","1.9.7","1.9.6","1.9.5","1.9.4","1.9.3","1.8.8","1.8.7","1.8.6","1.8.5","1.8.4","1.8.3","1.8.2","1.7.24","1.7.23","1.7.22","1.7.21","1.7.20","1.7.19","1.7.18","1.7.17","1.7.16","1.7.15","1.7.11","1.7.10","1.7.9","1.7.8","1.7.7","1.7.6","1.7.5","1.7.4","1.7.3","1.7.1","1.7.0","1.6.1","1.6.0","1.5.13","1.5.12","1.5.11","1.5.10","1.5.9","1.5.8","1.5.7","1.5.6"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2017-14737.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"}]}