CVE-2016-2195: Botan Project Botan

Critical severity, CVSS 9.8. EPSS: 6.7% chance of exploitation in the next 30 days.

Integer overflow in the PointGFp constructor in Botan before 1.10.11 and 1.11.x before 1.11.27 allows remote attackers to overwrite memory and possibly execute arbitrary code via a crafted ECC point, which triggers a heap-based buffer overflow.

Affected products

  • Botan Project Botan: up to and including 1.10.10; version 1.11.0 only; version 1.11.1 only; version 1.11.2 only; version 1.11.3 only; version 1.11.4 only; …
  • Debian Debian Linux: version 8.0 only

Published 2016-05-13. Last modified 2026-06-17.