{"id":"CVE-2016-2194","details":"The ressol function in Botan before 1.10.11 and 1.11.x before 1.11.27 allows remote attackers to cause a denial of service (infinite loop) via unspecified input to the OS2ECP function, related to a composite modulus.","modified":"2026-07-08T05:48:26.424730597Z","published":"2016-05-13T14:59:07.697Z","related":["SUSE-SU-2017:1222-1","openSUSE-SU-2024:10477-1"],"database_specific":{"unresolved_ranges":[{"source":"CPE_RANGE","vendor_product":"botan_project:botan","cpes":["cpe:2.3:a:botan_project:botan:*:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"1.10.10"}]},{"vendor_product":"debian:debian_linux","cpes":["cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"8.0"},{"last_affected":"8.0"}],"source":"CPE_STRING"}]},"references":[{"type":"ADVISORY","url":"http://botan.randombit.net/security.html"},{"type":"ADVISORY","url":"http://marc.info/?l=botan-devel&m=145435148602911&w=2"},{"type":"ADVISORY","url":"http://marc.info/?l=botan-devel&m=145449001708138&w=2"},{"type":"ADVISORY","url":"http://www.debian.org/security/2016/dsa-3565"},{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/201612-38"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/randombit/botan","events":[{"introduced":"ee912cd748a9b0bf56c84a49896dd2d57e0f81a6"},{"last_affected":"9d3ad9a0f44a9321185ed9f221c828dac81b9f0c"}],"database_specific":{"extracted_events":[{"introduced":"1.11.0"},{"last_affected":"1.11.0"},{"introduced":"1.11.1"},{"last_affected":"1.11.1"},{"introduced":"1.11.2"},{"last_affected":"1.11.2"},{"introduced":"1.11.3"},{"last_affected":"1.11.3"},{"introduced":"1.11.4"},{"last_affected":"1.11.4"},{"introduced":"1.11.5"},{"last_affected":"1.11.5"},{"introduced":"1.11.6"},{"last_affected":"1.11.6"},{"introduced":"1.11.7"},{"last_affected":"1.11.7"},{"introduced":"1.11.8"},{"last_affected":"1.11.8"},{"introduced":"1.11.9"},{"last_affected":"1.11.9"},{"introduced":"1.11.10"},{"last_affected":"1.11.10"},{"introduced":"1.11.11"},{"last_affected":"1.11.11"},{"introduced":"1.11.12"},{"last_affected":"1.11.12"},{"introduced":"1.11.13"},{"last_affected":"1.11.13"},{"introduced":"1.11.14"},{"last_affected":"1.11.14"},{"introduced":"1.11.15"},{"last_affected":"1.11.15"},{"introduced":"1.11.16"},{"last_affected":"1.11.16"},{"introduced":"1.11.17"},{"last_affected":"1.11.17"},{"introduced":"1.11.18"},{"last_affected":"1.11.18"},{"introduced":"1.11.19"},{"last_affected":"1.11.19"},{"introduced":"1.11.20"},{"last_affected":"1.11.20"},{"introduced":"1.11.21"},{"last_affected":"1.11.21"},{"introduced":"1.11.22"},{"last_affected":"1.11.22"},{"introduced":"1.11.23"},{"last_affected":"1.11.23"},{"introduced":"1.11.24"},{"last_affected":"1.11.24"},{"introduced":"1.11.25"},{"last_affected":"1.11.25"},{"introduced":"1.11.26"},{"last_affected":"1.11.26"}],"source":"CPE_STRING","cpe":["cpe:2.3:a:botan_project:botan:1.11.0:*:*:*:*:*:*:*","cpe:2.3:a:botan_project:botan:1.11.1:*:*:*:*:*:*:*","cpe:2.3:a:botan_project:botan:1.11.2:*:*:*:*:*:*:*","cpe:2.3:a:botan_project:botan:1.11.3:*:*:*:*:*:*:*","cpe:2.3:a:botan_project:botan:1.11.4:*:*:*:*:*:*:*","cpe:2.3:a:botan_project:botan:1.11.5:*:*:*:*:*:*:*","cpe:2.3:a:botan_project:botan:1.11.6:*:*:*:*:*:*:*","cpe:2.3:a:botan_project:botan:1.11.7:*:*:*:*:*:*:*","cpe:2.3:a:botan_project:botan:1.11.8:*:*:*:*:*:*:*","cpe:2.3:a:botan_project:botan:1.11.9:*:*:*:*:*:*:*","cpe:2.3:a:botan_project:botan:1.11.10:*:*:*:*:*:*:*","cpe:2.3:a:botan_project:botan:1.11.11:*:*:*:*:*:*:*","cpe:2.3:a:botan_project:botan:1.11.12:*:*:*:*:*:*:*","cpe:2.3:a:botan_project:botan:1.11.13:*:*:*:*:*:*:*","cpe:2.3:a:botan_project:botan:1.11.14:*:*:*:*:*:*:*","cpe:2.3:a:botan_project:botan:1.11.15:*:*:*:*:*:*:*","cpe:2.3:a:botan_project:botan:1.11.16:*:*:*:*:*:*:*","cpe:2.3:a:botan_project:botan:1.11.17:*:*:*:*:*:*:*","cpe:2.3:a:botan_project:botan:1.11.18:*:*:*:*:*:*:*","cpe:2.3:a:botan_project:botan:1.11.19:*:*:*:*:*:*:*","cpe:2.3:a:botan_project:botan:1.11.20:*:*:*:*:*:*:*","cpe:2.3:a:botan_project:botan:1.11.21:*:*:*:*:*:*:*","cpe:2.3:a:botan_project:botan:1.11.22:*:*:*:*:*:*:*","cpe:2.3:a:botan_project:botan:1.11.23:*:*:*:*:*:*:*","cpe:2.3:a:botan_project:botan:1.11.24:*:*:*:*:*:*:*","cpe:2.3:a:botan_project:botan:1.11.25:*:*:*:*:*:*:*","cpe:2.3:a:botan_project:botan:1.11.26:*:*:*:*:*:*:*"]}}],"versions":["1.11.0","1.11.1","1.11.10","1.11.11","1.11.12","1.11.13","1.11.14","1.11.15","1.11.16","1.11.17","1.11.18","1.11.19","1.11.2","1.11.20","1.11.21","1.11.22","1.11.23","1.11.24","1.11.25","1.11.26","1.11.3","1.11.4","1.11.5","1.11.6","1.11.7","1.11.8","1.11.9"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-2194.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}