Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-28052

Опубликовано: 18 дек. 2020
Источник: debian

Описание

An issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and 1.66. The OpenBSDBCrypt.checkPassword utility method compared incorrect data when checking the password, allowing incorrect passwords to indicate they were matching with previously hashed ones that were different.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
bouncycastlefixed1.65-2package
bouncycastlenot-affectedbusterpackage
bouncycastlenot-affectedstretchpackage

Примечания

  • https://github.com/bcgit/bc-java/wiki/CVE-2020-28052

  • https://www.synopsys.com/blogs/software-security/cve-2020-28052-bouncy-castle/

  • Introduced in: https://github.com/bcgit/bc-java/commit/00dfe74aeb4f6300dd56b34b5e6986ce6658617e (r1rv65)

  • Fixed by: https://github.com/bcgit/bc-java/commit/97578f9b7ed277e6ecb58834e85e3d18385a4219 (r1rv67)

Связанные уязвимости

CVSS3: 8.1
ubuntu
больше 5 лет назад

An issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and 1.66. The OpenBSDBCrypt.checkPassword utility method compared incorrect data when checking the password, allowing incorrect passwords to indicate they were matching with previously hashed ones that were different.

CVSS3: 8.1
redhat
больше 5 лет назад

An issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and 1.66. The OpenBSDBCrypt.checkPassword utility method compared incorrect data when checking the password, allowing incorrect passwords to indicate they were matching with previously hashed ones that were different.

CVSS3: 8.1
nvd
больше 5 лет назад

An issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and 1.66. The OpenBSDBCrypt.checkPassword utility method compared incorrect data when checking the password, allowing incorrect passwords to indicate they were matching with previously hashed ones that were different.

CVSS3: 8.1
github
больше 5 лет назад

Logic error in Legion of the Bouncy Castle BC Java

Уязвимость CVE-2020-28052