The Bouncy Castle Java library before 1.51 does not validate a point is withing the elliptic curve, which makes it easier for remote attackers to obtain private keys via a series of crafted elliptic curve Diffie Hellman (ECDH) key exchanges, aka an "invalid curve attack."
CVSS Details
- CVSS 3.1 Base Score: 3.7
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade bouncycastle | Dec 18, 2015 | Nov 9, 2015 |
| Oracle Weblogic | — | Apply the Patch Set Update (PSU) 27338939 for version 12.2.1.2.0.Apply the Patch Set Update (PSU) 27419391 for version 12.1.3.0.0. | May 24, 2018 | Nov 9, 2015 |
| Suse | — | Upgrade bouncycastle-pgUpgrade bouncycastle | Dec 18, 2015 | Nov 9, 2015 |
| Ubuntu | — | Upgrade libbcprov-javaUpgrade libbcpkix-javaUpgrade libbcmail-javaUpgrade libbcpg-java | Aug 8, 2018 | Nov 9, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub