{"id":"UBUNTU-CVE-2022-43705","details":"In Botan before 2.19.3, it is possible to forge OCSP responses due to a certificate verification error. This issue was introduced in Botan 1.11.34 (November 2016).","modified":"2026-04-22T13:30:41.097233Z","published":"2022-11-27T04:15:00Z","upstream":["CVE-2022-43705"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2022-43705"},{"type":"REPORT","url":"https://github.com/randombit/botan/security/advisories/GHSA-4v9w-qvcq-6q7w"},{"type":"REPORT","url":"https://github.com/randombit/botan/commit/fd83d9e262f63fb673e4c13ca37e5b768e41e812"},{"type":"REPORT","url":"https://github.com/randombit/botan/commit/4e35073ff356e37c3adcf1ff3522e9d0d48c765f"},{"type":"REPORT","url":"https://github.com/randombit/botan/commit/c2faa88b0281e5017be72e1c85d0c41f686e1928"},{"type":"REPORT","url":"https://github.com/randombit/botan/commit/5d8d9fbf75c8b814ea609161bee525d520f5cb57"},{"type":"REPORT","url":"https://github.com/randombit/botan/commit/1829ef9d89614da1eacdf511356bdf98a970f5f5"},{"type":"REPORT","url":"https://github.com/randombit/botan/commit/991b0159282781f2d5c06ff42a9ff00ee563e96b"},{"type":"REPORT","url":"https://github.com/randombit/botan/commit/a33689613127f319c0047fb96f092de16e7cb350"},{"type":"REPORT","url":"https://github.com/randombit/botan/commit/909c62717855402e04dbaf8ffc085f444d547aae"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2022-43705"}],"affected":[{"package":{"name":"botan","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/botan@2.4.0-5ubuntu1?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.4.0-3","2.4.0-4","2.4.0-5ubuntu1"],"ecosystem_specific":{"binaries":[{"binary_name":"botan","binary_version":"2.4.0-5ubuntu1"},{"binary_name":"libbotan-2-4","binary_version":"2.4.0-5ubuntu1"},{"binary_name":"python3-botan","binary_version":"2.4.0-5ubuntu1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-43705.json"}},{"package":{"name":"botan","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/botan@2.12.1-2build1?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.9.0-2","2.9.0-2build1","2.12.1-2","2.12.1-2build1"],"ecosystem_specific":{"binaries":[{"binary_name":"botan","binary_version":"2.12.1-2build1"},{"binary_name":"libbotan-2-12","binary_version":"2.12.1-2build1"},{"binary_name":"python3-botan","binary_version":"2.12.1-2build1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-43705.json"}},{"package":{"name":"botan","ecosystem":"Ubuntu:Pro:22.04:LTS","purl":"pkg:deb/ubuntu/botan@2.19.1+dfsg-2ubuntu1+esm1?arch=source&distro=esm-apps/jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.17.3+dfsg-3","2.19.1+dfsg-2ubuntu1","2.19.1+dfsg-2ubuntu1+esm1"],"ecosystem_specific":{"binaries":[{"binary_name":"botan","binary_version":"2.19.1+dfsg-2ubuntu1+esm1"},{"binary_name":"libbotan-2-19","binary_version":"2.19.1+dfsg-2ubuntu1+esm1"},{"binary_name":"python3-botan","binary_version":"2.19.1+dfsg-2ubuntu1+esm1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-43705.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"},{"type":"Ubuntu","score":"medium"}]}