{"id":"openSUSE-SU-2024:0201-1","summary":"Security update for Botan","details":"This update for Botan fixes the following issues:\n\nUpdate to 2.19.5:\n\n* Fix multiple Denial of service attacks due to X.509 cert processing:\n* CVE-2024-34702 - boo#1227238\n* CVE-2024-34703 - boo#1227607\n* CVE-2024-39312 - boo#1227608\n* Fix a crash in OCB\n* Fix a test failure in compression with certain versions of zlib \n* Fix some iterator debugging errors in TLS CBC decryption. \n* Avoid a miscompilation in ARIA when using XCode 14 \n","modified":"2026-03-11T07:33:32.795222Z","published":"2024-07-16T06:28:15Z","related":["CVE-2024-34702","CVE-2024-34703","CVE-2024-39312"],"upstream":["CVE-2024-34702","CVE-2024-34703","CVE-2024-39312"],"references":[{"type":"ADVISORY","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/6IOSLFSD2TJGWL4XB37VIQSVW7SPG2IP/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1227238"},{"type":"REPORT","url":"https://bugzilla.suse.com/1227607"},{"type":"REPORT","url":"https://bugzilla.suse.com/1227608"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-34702"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-34703"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-39312"}],"affected":[{"package":{"name":"Botan","ecosystem":"SUSE:Package Hub 15 SP5","purl":"pkg:rpm/suse/Botan&distro=SUSE%20Package%20Hub%2015%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.19.5-bp155.2.3.1"}]}],"ecosystem_specific":{"binaries":[{"Botan-doc":"2.19.5-bp155.2.3.1","libbotan-2-19-32bit":"2.19.5-bp155.2.3.1","libbotan-2-19":"2.19.5-bp155.2.3.1","libbotan-devel":"2.19.5-bp155.2.3.1","Botan":"2.19.5-bp155.2.3.1","libbotan-2-19-64bit":"2.19.5-bp155.2.3.1","libbotan-devel-32bit":"2.19.5-bp155.2.3.1","libbotan-devel-64bit":"2.19.5-bp155.2.3.1","python3-botan":"2.19.5-bp155.2.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2024:0201-1.json"}},{"package":{"name":"Botan","ecosystem":"openSUSE:Leap 15.5","purl":"pkg:rpm/opensuse/Botan&distro=openSUSE%20Leap%2015.5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.19.5-bp155.2.3.1"}]}],"ecosystem_specific":{"binaries":[{"libbotan-2-19":"2.19.5-bp155.2.3.1","libbotan-devel-32bit":"2.19.5-bp155.2.3.1","libbotan-devel-64bit":"2.19.5-bp155.2.3.1","python3-botan":"2.19.5-bp155.2.3.1","Botan-doc":"2.19.5-bp155.2.3.1","Botan":"2.19.5-bp155.2.3.1","libbotan-2-19-32bit":"2.19.5-bp155.2.3.1","libbotan-2-19-64bit":"2.19.5-bp155.2.3.1","libbotan-devel":"2.19.5-bp155.2.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2024:0201-1.json"}}],"schema_version":"1.7.5"}