PT-2015-2750 · Bouncy Castle+3 · Bouncy Castle Java Library+4

Publicado

2015-11-04

·

Atualizado

2024-06-15

·

CVE-2015-7940

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Bouncy Castle Java library versions prior to 1.51 openSUSE (affected versions not specified)
Description The issue is related to an "invalid curve attack" where remote attackers can obtain private keys via a series of crafted elliptic curve Diffie Hellman (ECDH) key exchanges due to the lack of validation of a point within the elliptic curve. This can be exploited by making changes to the elliptic curve Diffie-Hellman algorithm, allowing an attacker to gain access to the private key.
Recommendations For Bouncy Castle Java library versions prior to 1.51, update to version 1.51 or later to resolve the issue. For openSUSE, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-12115
CVE-2015-7940
DLA-361-1
DSA-3417-1
GHSA-4MV7-CQ75-3QJM
MGASA-2015-0487
OPENSUSE-SU-2015_1911-1
OPENSUSE-SU-2024:10486-1
USN-3727-1

Produtos afetados

Bouncy Castle Java Library
Jira
Suse
Ubuntu
Opensuse