CVE-2018-9860 is an off-by-one error in Botan versions 1.11.32 through 2.x before 2.6.0, affecting the processing of malformed TLS-CBC ciphertext. This vulnerability can lead to a denial-of-service condition by causing the receiving side to over-read 64KB of data for HMAC computation, subsequently failing the MAC comparison and closing the connection. Rated as High severity (CVSS 7.5), it requires no user interaction and has low attack complexity, though no information leakage occurs. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.11.32, < 2.6.0CPE matchmatch criteria | cpe:2.3:a:botan_project:botan:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.