Randombit Botan is prone to a security-bypass vulnerability.
Successfully exploiting this issue allows attackers to perform man-in-the-middle attacks or impersonate trusted servers, which will aid in further attacks.
Randombit Botan version 2.0.1 is vulnerable; other versions may also be affected.
Information
Exploit
The researcher has created a proof-of-concept to demonstrate the issue. Please see the references for more information.
References:
- RANDOMBIT BOTAN LIBRARY X509 CERTIFICATE VALIDATION BYPASS VULNERABILITY (talosintelligence)
- Vendor Homepage (randombit)
- Vulnerability Spotlight: Randombit Botan Library X509 Certificate Validation Byp (talosintelligence)