Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-28052

Опубликовано: 18 дек. 2020
Источник: debian
EPSS Низкий

Описание

An issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and 1.66. The OpenBSDBCrypt.checkPassword utility method compared incorrect data when checking the password, allowing incorrect passwords to indicate they were matching with previously hashed ones that were different.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
bouncycastlefixed1.65-2package
bouncycastlenot-affectedbusterpackage
bouncycastlenot-affectedstretchpackage

Примечания

  • https://github.com/bcgit/bc-java/wiki/CVE-2020-28052

  • https://www.synopsys.com/blogs/software-security/cve-2020-28052-bouncy-castle/

  • Introduced in: https://github.com/bcgit/bc-java/commit/00dfe74aeb4f6300dd56b34b5e6986ce6658617e (r1rv65)

  • Fixed by: https://github.com/bcgit/bc-java/commit/97578f9b7ed277e6ecb58834e85e3d18385a4219 (r1rv67)

EPSS

Процентиль: 86%
0.0306
Низкий

Связанные уязвимости

CVSS3: 8.1
ubuntu
около 5 лет назад

An issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and 1.66. The OpenBSDBCrypt.checkPassword utility method compared incorrect data when checking the password, allowing incorrect passwords to indicate they were matching with previously hashed ones that were different.

CVSS3: 8.1
redhat
около 5 лет назад

An issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and 1.66. The OpenBSDBCrypt.checkPassword utility method compared incorrect data when checking the password, allowing incorrect passwords to indicate they were matching with previously hashed ones that were different.

CVSS3: 8.1
nvd
около 5 лет назад

An issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and 1.66. The OpenBSDBCrypt.checkPassword utility method compared incorrect data when checking the password, allowing incorrect passwords to indicate they were matching with previously hashed ones that were different.

CVSS3: 8.1
github
почти 5 лет назад

Logic error in Legion of the Bouncy Castle BC Java

EPSS

Процентиль: 86%
0.0306
Низкий