PT-2018-4634 · Bouncy Castle+1 · Bouncy Castle Jce Provider+1

Published

2018-06-04

·

Updated

2025-05-12

·

CVE-2016-1000340

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Bouncy Castle JCE Provider versions 1.51 through 1.55
Description A carry propagation bug was introduced in the implementation of squaring for several raw math classes, which are used by custom elliptic curve implementations. This bug could have led to rare spurious calculations for elliptic curve scalar multiplications. However, such errors would have been detected with high probability by the output validation for scalar multipliers.
Recommendations For Bouncy Castle JCE Provider versions 1.51 through 1.55, update to a version that includes the fix for the carry propagation bug in the raw math classes.

Fix

Weakness Enumeration

Related Identifiers

CVE-2016-1000340
GHSA-R97X-3G8F-GX3M
MGASA-2018-0376
OPENSUSE-SU-2018_1689-1
OPENSUSE-SU-2024:10661-1
RHSA-2018:2927

Affected Products

Bouncy Castle Jce Provider
Suse