GSA-6412-1: Botan3 Security Update – Cryptographic Vulnerabilities Fixed
An urgent security update for the Botan3 library addresses multiple cryptographic weaknesses. Gnoppix 23/25 and Gnoppix 25 users must apply this patch immediately.
Botan3 is a cross-platform cryptographic library used for secure protocols and data encryption.
Affected Packages:
- Botan3 library (bundle botan3)
Impact:
Attackers could exploit these flaws to weaken encryption or forge signatures, potentially leading to unauthorized data access or system compromise.
Critical Warning: Unpatched systems are vulnerable to attacks that bypass cryptographic protections. Immediate upgrade is required.
Resolution:
Upgrade the botan3 package to the fixed version via the official Gnoppix package manager.
Background:
The vulnerabilities stem from incorrectly handled edge cases in random number generation and key exchange validation. Maintenance updates provide hardened code and stricter parameter checks. - Please update your systems.