PT-2018-4634 · Bouncy Castle+1 · Bouncy Castle Jce Provider+1
Published
2018-06-04
·
Updated
2025-05-12
·
CVE-2016-1000340
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Bouncy Castle JCE Provider versions 1.51 through 1.55
Description
A carry propagation bug was introduced in the implementation of squaring for several raw math classes, which are used by custom elliptic curve implementations. This bug could have led to rare spurious calculations for elliptic curve scalar multiplications. However, such errors would have been detected with high probability by the output validation for scalar multipliers.
Recommendations
For Bouncy Castle JCE Provider versions 1.51 through 1.55, update to a version that includes the fix for the carry propagation bug in the raw math classes.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bouncy Castle Jce Provider
Suse