In the Bouncy Castle JCE Provider version 1.55 and earlier the other party DH public key is not fully validated. This can cause issues as invalid keys can be used to reveal details about the other party's private key where static Diffie-Hellman is in use. As of release 1.56 the key parameters are checked on agreement calculation.
CVSS Details
- CVSS 3.1 Base Score: 3.7
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade bouncycastle | Feb 20, 2019 | Jun 4, 2018 |
| Suse | — | Upgrade bouncycastleUpgrade bouncycastle-pg | Jun 16, 2018 | Jun 4, 2018 |
| Ubuntu | — | Upgrade libbcpg-javaUpgrade libbcpkix-javaUpgrade libbcprov-javaUpgrade libbcmail-java | Aug 8, 2018 | Jun 4, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub