{"affected":[{"ecosystem_specific":{"binaries":[{"Botan":"2.19.5-bp155.2.3.1","Botan-doc":"2.19.5-bp155.2.3.1","libbotan-2-19":"2.19.5-bp155.2.3.1","libbotan-2-19-32bit":"2.19.5-bp155.2.3.1","libbotan-2-19-64bit":"2.19.5-bp155.2.3.1","libbotan-devel":"2.19.5-bp155.2.3.1","libbotan-devel-32bit":"2.19.5-bp155.2.3.1","libbotan-devel-64bit":"2.19.5-bp155.2.3.1","python3-botan":"2.19.5-bp155.2.3.1"}]},"package":{"ecosystem":"SUSE:Package Hub 15 SP5","name":"Botan","purl":"pkg:rpm/suse/Botan&distro=SUSE%20Package%20Hub%2015%20SP5"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.19.5-bp155.2.3.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"Botan":"2.19.5-bp155.2.3.1","Botan-doc":"2.19.5-bp155.2.3.1","libbotan-2-19":"2.19.5-bp155.2.3.1","libbotan-2-19-32bit":"2.19.5-bp155.2.3.1","libbotan-2-19-64bit":"2.19.5-bp155.2.3.1","libbotan-devel":"2.19.5-bp155.2.3.1","libbotan-devel-32bit":"2.19.5-bp155.2.3.1","libbotan-devel-64bit":"2.19.5-bp155.2.3.1","python3-botan":"2.19.5-bp155.2.3.1"}]},"package":{"ecosystem":"openSUSE:Leap 15.5","name":"Botan","purl":"pkg:rpm/opensuse/Botan&distro=openSUSE%20Leap%2015.5"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.19.5-bp155.2.3.1"}],"type":"ECOSYSTEM"}]}],"aliases":[],"details":"This update for Botan fixes the following issues:\n\nUpdate to 2.19.5:\n\n* Fix multiple Denial of service attacks due to X.509 cert processing:\n* CVE-2024-34702 - boo#1227238\n* CVE-2024-34703 - boo#1227607\n* CVE-2024-39312 - boo#1227608\n* Fix a crash in OCB\n* Fix a test failure in compression with certain versions of zlib \n* Fix some iterator debugging errors in TLS CBC decryption. \n* Avoid a miscompilation in ARIA when using XCode 14 \n","id":"openSUSE-SU-2024:0201-1","modified":"2024-07-16T06:28:15Z","published":"2024-07-16T06:28:15Z","references":[{"type":"ADVISORY","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/6IOSLFSD2TJGWL4XB37VIQSVW7SPG2IP/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1227238"},{"type":"REPORT","url":"https://bugzilla.suse.com/1227607"},{"type":"REPORT","url":"https://bugzilla.suse.com/1227608"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-34702"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-34703"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-39312"}],"related":["CVE-2024-34702","CVE-2024-34703","CVE-2024-39312"],"summary":"Security update for Botan","upstream":["CVE-2024-34702","CVE-2024-34703","CVE-2024-39312"]}