In the Bouncy Castle JCE Provider version 1.55 and earlier ECDSA does not fully validate ASN.1 encoding of signature on verification. It is possible to inject extra elements in the sequence making up the signature and still have it validate, which in some cases may allow the introduction of 'invisible' data into a signed structure.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade bouncycastle | Feb 20, 2019 | Jun 4, 2018 |
| Suse | — | Upgrade bouncycastle-pgUpgrade bouncycastle | Jun 16, 2018 | Jun 4, 2018 |
| Ubuntu | — | Upgrade libbcmail-javaUpgrade libbcpg-javaUpgrade libbcprov-javaUpgrade libbcpkix-java | Aug 8, 2018 | Jun 4, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub