PT-2018-4640 · Bouncy Castle+3 · Bouncy Castle Jce Provider+3

Published

2018-06-04

·

Updated

2024-06-15

·

CVE-2016-1000346

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Bouncy Castle JCE Provider versions prior to 1.56
Description The issue arises from insufficient validation of the other party's Diffie-Hellman public key, potentially allowing invalid keys to reveal details about the other party's private key when static Diffie-Hellman is used.
Recommendations For Bouncy Castle JCE Provider versions prior to 1.56, update to version 1.56 or later, where key parameters are checked during agreement calculation to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-1000346
DLA-1418-1
GHSA-FJQM-246C-MWQG
MGASA-2018-0376
OPENSUSE-SU-2018_1689-1
OPENSUSE-SU-2024:10661-1
RHSA-2018:2927
USN-3727-1

Affected Products

Bouncy Castle Jce Provider
Jira
Suse
Ubuntu