Botan before 1.10.13 and 1.11.x before 1.11.22 make it easier for remote attackers to conduct million-message attacks by measuring time differences, related to decoding of PKCS#1 padding.
http://www.debian.org/security/2016/dsa-3565
http://marc.info/?l=botan-devel&m=146185420505943&w=2
http://lists.fedoraproject.org/pipermail/package-announce/2016-May/183669.html