PT-2018-4640 · Bouncy Castle+3 · Bouncy Castle Jce Provider+3
Publicado
2018-06-04
·
Atualizado
2024-06-15
·
CVE-2016-1000346
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Bouncy Castle JCE Provider versions prior to 1.56
Description
The issue arises from insufficient validation of the other party's Diffie-Hellman public key, potentially allowing invalid keys to reveal details about the other party's private key when static Diffie-Hellman is used.
Recommendations
For Bouncy Castle JCE Provider versions prior to 1.56, update to version 1.56 or later, where key parameters are checked during agreement calculation to resolve the issue.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Bouncy Castle Jce Provider
Jira
Suse
Ubuntu