Critical severity9.8NVD Advisory· Published May 13, 2016· Updated Jun 17, 2026
CVE-2016-2195
CVE-2016-2195
Description
Integer overflow in the PointGFp constructor in Botan before 1.10.11 and 1.11.x before 1.11.27 allows remote attackers to overwrite memory and possibly execute arbitrary code via a crafted ECC point, which triggers a heap-based buffer overflow.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
33cpe:2.3:a:botan_project:botan:*:*:*:*:*:*:*:*+ 28 more
- cpe:2.3:a:botan_project:botan:*:*:*:*:*:*:*:*range: <=1.10.10
- cpe:2.3:a:botan_project:botan:1.11.0:*:*:*:*:*:*:*
- cpe:2.3:a:botan_project:botan:1.11.1:*:*:*:*:*:*:*
- cpe:2.3:a:botan_project:botan:1.11.10:*:*:*:*:*:*:*
- cpe:2.3:a:botan_project:botan:1.11.11:*:*:*:*:*:*:*
- cpe:2.3:a:botan_project:botan:1.11.12:*:*:*:*:*:*:*
- cpe:2.3:a:botan_project:botan:1.11.13:*:*:*:*:*:*:*
- cpe:2.3:a:botan_project:botan:1.11.14:*:*:*:*:*:*:*
- cpe:2.3:a:botan_project:botan:1.11.15:*:*:*:*:*:*:*
- cpe:2.3:a:botan_project:botan:1.11.16:*:*:*:*:*:*:*
- cpe:2.3:a:botan_project:botan:1.11.17:*:*:*:*:*:*:*
- cpe:2.3:a:botan_project:botan:1.11.18:*:*:*:*:*:*:*
- cpe:2.3:a:botan_project:botan:1.11.19:*:*:*:*:*:*:*
- cpe:2.3:a:botan_project:botan:1.11.2:*:*:*:*:*:*:*
- cpe:2.3:a:botan_project:botan:1.11.20:*:*:*:*:*:*:*
- cpe:2.3:a:botan_project:botan:1.11.21:*:*:*:*:*:*:*
- cpe:2.3:a:botan_project:botan:1.11.22:*:*:*:*:*:*:*
- cpe:2.3:a:botan_project:botan:1.11.23:*:*:*:*:*:*:*
- cpe:2.3:a:botan_project:botan:1.11.24:*:*:*:*:*:*:*
- cpe:2.3:a:botan_project:botan:1.11.25:*:*:*:*:*:*:*
- cpe:2.3:a:botan_project:botan:1.11.26:*:*:*:*:*:*:*
- cpe:2.3:a:botan_project:botan:1.11.3:*:*:*:*:*:*:*
- cpe:2.3:a:botan_project:botan:1.11.4:*:*:*:*:*:*:*
- cpe:2.3:a:botan_project:botan:1.11.5:*:*:*:*:*:*:*
- cpe:2.3:a:botan_project:botan:1.11.6:*:*:*:*:*:*:*
- cpe:2.3:a:botan_project:botan:1.11.7:*:*:*:*:*:*:*
- cpe:2.3:a:botan_project:botan:1.11.8:*:*:*:*:*:*:*
- cpe:2.3:a:botan_project:botan:1.11.9:*:*:*:*:*:*:*
- (no CPE)range: <=1.10.10, >=1.11.0 <1.11.27
- osv-coords3 versionspkg:rpm/opensuse/Botan&distro=openSUSE%20Tumbleweedpkg:rpm/suse/Botan&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP1pkg:rpm/suse/Botan&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP2
< 1.10.13-1.1+ 2 more
- (no CPE)range: < 1.10.13-1.1
- (no CPE)range: < 1.10.9-3.1
- (no CPE)range: < 1.10.9-3.1
Patches
Vulnerability mechanics
References
4- botan.randombit.net/security.htmlnvdVendor Advisory
- marc.infonvdVendor Advisory
- www.debian.org/security/2016/dsa-3565nvd
- security.gentoo.org/glsa/201612-38nvd
News mentions
0No linked articles in our index yet.