CVE-2017-14737: Botan Project Botan
Medium severity, CVSS 5.5. EPSS: 0.3% chance of exploitation in the next 30 days.
A cryptographic cache-based side channel in the RSA implementation in Botan before 1.10.17, and 1.11.x and 2.x before 2.3.0, allows a local attacker to recover information about RSA secret keys, as demonstrated by CacheD. This occurs because an array is indexed with bits derived from a secret key.
Affected products
- Botan Project Botan: up to and including 1.10.16; version 1.11.0 only; version 1.11.1 only; version 1.11.2 only; version 1.11.3 only; version 1.11.4 only; …
- Debian Debian Linux: version 9.0 only
Published 2017-09-26. Last modified 2026-06-17.