VYPR
Critical severity9.8NVD Advisory· Published May 13, 2016· Updated May 6, 2026

CVE-2016-2196

CVE-2016-2196

Description

Heap-based buffer overflow in the P-521 reduction function in Botan 1.11.x before 1.11.27 allows remote attackers to cause a denial of service (memory overwrite and crash) or execute arbitrary code via unspecified vectors.

Affected products

27
  • Botan Project/Botan27 versions
    cpe:2.3:a:botan_project:botan:1.11.0:*:*:*:*:*:*:*+ 26 more
    • cpe:2.3:a:botan_project:botan:1.11.0:*:*:*:*:*:*:*
    • cpe:2.3:a:botan_project:botan:1.11.1:*:*:*:*:*:*:*
    • cpe:2.3:a:botan_project:botan:1.11.10:*:*:*:*:*:*:*
    • cpe:2.3:a:botan_project:botan:1.11.11:*:*:*:*:*:*:*
    • cpe:2.3:a:botan_project:botan:1.11.12:*:*:*:*:*:*:*
    • cpe:2.3:a:botan_project:botan:1.11.13:*:*:*:*:*:*:*
    • cpe:2.3:a:botan_project:botan:1.11.14:*:*:*:*:*:*:*
    • cpe:2.3:a:botan_project:botan:1.11.15:*:*:*:*:*:*:*
    • cpe:2.3:a:botan_project:botan:1.11.16:*:*:*:*:*:*:*
    • cpe:2.3:a:botan_project:botan:1.11.17:*:*:*:*:*:*:*
    • cpe:2.3:a:botan_project:botan:1.11.18:*:*:*:*:*:*:*
    • cpe:2.3:a:botan_project:botan:1.11.19:*:*:*:*:*:*:*
    • cpe:2.3:a:botan_project:botan:1.11.2:*:*:*:*:*:*:*
    • cpe:2.3:a:botan_project:botan:1.11.20:*:*:*:*:*:*:*
    • cpe:2.3:a:botan_project:botan:1.11.21:*:*:*:*:*:*:*
    • cpe:2.3:a:botan_project:botan:1.11.22:*:*:*:*:*:*:*
    • cpe:2.3:a:botan_project:botan:1.11.23:*:*:*:*:*:*:*
    • cpe:2.3:a:botan_project:botan:1.11.24:*:*:*:*:*:*:*
    • cpe:2.3:a:botan_project:botan:1.11.25:*:*:*:*:*:*:*
    • cpe:2.3:a:botan_project:botan:1.11.26:*:*:*:*:*:*:*
    • cpe:2.3:a:botan_project:botan:1.11.3:*:*:*:*:*:*:*
    • cpe:2.3:a:botan_project:botan:1.11.4:*:*:*:*:*:*:*
    • cpe:2.3:a:botan_project:botan:1.11.5:*:*:*:*:*:*:*
    • cpe:2.3:a:botan_project:botan:1.11.6:*:*:*:*:*:*:*
    • cpe:2.3:a:botan_project:botan:1.11.7:*:*:*:*:*:*:*
    • cpe:2.3:a:botan_project:botan:1.11.8:*:*:*:*:*:*:*
    • cpe:2.3:a:botan_project:botan:1.11.9:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.