VDB
CVE-2018-9127
CVE-2018-9127
PUBLISHED
Botan 2.2.0 - 2.4.0 (fixed in 2.5.0) improperly handled wildcard certificates and could accept certain certificates as valid for hostnames when, under RFC 6125 rules, they should not match. This only affects certificates issued to the same domain as the host, so to impersonate a host one must already have a wildcard certificate matching other hosts in the same domain. For example, b*.example.com would match some hostnames that do not begin with a 'b' character.
EPSS 0.18% · 39.6th percentile
Risk Scores
EPSS Score
0.18%
39.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:Pro:22.04:LTS | botan | 0, 2.17.3+dfsg-3, 2.19.1+dfsg-2ubuntu1 |
| Ubuntu:20.04:LTS | botan | 0, 2.12.1-2, 2.9.0-2 |
Timeline
- Apr 2, 2018 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 22, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Oct 25, 2021 EPSS Score
- Dec 27, 2021 EPSS Score
- Feb 27, 2022 EPSS Score
- May 1, 2022 EPSS Score
- Jul 2, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Nov 5, 2022 EPSS Score
- Jan 7, 2023 EPSS Score
References
- https://ubuntu.com/security/CVE-2018-9127 third-party-advisory
- https://botan.randombit.net/security.html third-party-advisory
- https://www.cve.org/CVERecord?id=CVE-2018-9127 third-party-advisory