Show plain JSON{"id": "CVE-2016-8871", "cveTags": [], "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 2.1, "accessVector": "LOCAL", "vectorString": "AV:L/AC:L/Au:N/C:P/I:N/A:N", "authentication": "NONE", "integrityImpact": "NONE", "accessComplexity": "LOW", "availabilityImpact": "NONE", "confidentialityImpact": "PARTIAL"}, "acInsufInfo": false, "impactScore": 2.9, "baseSeverity": "LOW", "obtainAllPrivilege": false, "exploitabilityScore": 3.9, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false}], "cvssMetricV30": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"scope": "UNCHANGED", "version": "3.0", "baseScore": 6.2, "attackVector": "LOCAL", "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", "integrityImpact": "NONE", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "NONE", "privilegesRequired": "NONE", "confidentialityImpact": "HIGH"}, "impactScore": 3.6, "exploitabilityScore": 2.5}]}, "published": "2016-10-28T15:59:15.470", "references": [{"url": "http://www.securityfocus.com/bid/94225", "tags": ["Third Party Advisory", "VDB Entry"], "source": "cve@mitre.org"}, {"url": "https://botan.randombit.net/security.html", "tags": ["Vendor Advisory"], "source": "cve@mitre.org"}, {"url": "http://www.securityfocus.com/bid/94225", "tags": ["Third Party Advisory", "VDB Entry"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "https://botan.randombit.net/security.html", "tags": ["Vendor Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Deferred", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-200"}]}], "descriptions": [{"lang": "en", "value": "In Botan 1.11.29 through 1.11.32, RSA decryption with certain padding options had a detectable timing channel which could given sufficient queries be used to recover plaintext, aka an \"OAEP side channel\" attack."}, {"lang": "es", "value": "En Botan 1.11.29 hasta la versi\u00f3n 1.11.32, descifrado RSA con ciertas opciones de relleno ten\u00eda un canal de sincronizaci\u00f3n detectable lo que podr\u00eda dadas las suficientes consultas, se utilizado para recuperar texto plano, vulnerabilidad tambi\u00e9n conocida como un ataque \"OAEP side channel\"."}], "lastModified": "2025-04-12T10:46:40.837", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:botan_project:botan:1.11.29:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B31BCFA3-67C3-4AAF-A558-902FAFEC3C1B"}, {"criteria": "cpe:2.3:a:botan_project:botan:1.11.30:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "434C1EF2-D18A-4459-AF5B-57858A2C1DA7"}, {"criteria": "cpe:2.3:a:botan_project:botan:1.11.31:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "292DE6D3-FFCF-4BFC-AC2F-F030B291CFF3"}, {"criteria": "cpe:2.3:a:botan_project:botan:1.11.32:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AA217C5B-E6AF-43F0-84A1-778B0FE3351F"}], "operator": "OR"}]}], "sourceIdentifier": "cve@mitre.org"}