Alpine: botan: security update to 2.19.4-r0

high Tenable Self-Hosted Container Security Plugin ID 408532

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Botan is a C++ cryptography library. X.509 certificates can identify elliptic curves using either an
object identifier or using explicit encoding of the parameters. Prior to versions 3.3.0 and 2.19.4, an
attacker could present an ECDSA X.509 certificate using explicit encoding where the parameters are very
large. The proof of concept used a 16Kbit prime for this purpose. When parsing, the parameter is checked
to be prime, causing excessive computation. This was patched in 2.19.4 and 3.3.0 to allow the prime
parameter of the elliptic curve to be at most 521 bits. No known workarounds are available. Note that
support for explicit encoding of elliptic curve parameters is deprecated in Botan. (CVE-2024-34703)

See Also

https://security.alpinelinux.org/vuln/CVE-2024-34703

Plugin Details

Severity: High

ID: 408532

Version: Revision 1.4

Type: Local

Published: 10/9/2024

Updated: 2/2/2026

Supported Sensors: Agentless Assessment

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.18

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS Score Source: CVE-2024-34703

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 6/30/2024

Reference Information

CVE: CVE-2024-34703