Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-6644

Опубликовано: 01 янв. 2016
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

Bouncy Castle in Android before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to obtain sensitive information via a crafted application, aka internal bug 24106146.

It was found that an information disclosure flaw in Bouncy Castle could enable a local malicious application to gain access to user's private information.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss A-MQ 6fabric8Affected
Red Hat Subscription Asset ManagerbouncycastleWill not fix
Red Hat JBoss A-MQ 6.3fabric8FixedRHSA-2017:183210.08.2017
Red Hat JBoss EAP 7FixedRHSA-2017:281026.09.2017
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6eap7-artemis-nativeFixedRHSA-2017:280926.09.2017
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6eap7-bouncycastleFixedRHSA-2017:280926.09.2017
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6eap7-hibernate-validatorFixedRHSA-2017:280926.09.2017
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6eap7-jasyptFixedRHSA-2017:280926.09.2017
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6eap7-jboss-jms-api_2.0_specFixedRHSA-2017:280926.09.2017
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6eap7-jboss-logmanagerFixedRHSA-2017:280926.09.2017

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-200
https://bugzilla.redhat.com/show_bug.cgi?id=1444015bouncycastle: Information disclosure in GCMBlockCipher

EPSS

Процентиль: 40%
0.00184
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 3.3
ubuntu
около 10 лет назад

Bouncy Castle in Android before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to obtain sensitive information via a crafted application, aka internal bug 24106146.

CVSS3: 3.3
nvd
около 10 лет назад

Bouncy Castle in Android before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to obtain sensitive information via a crafted application, aka internal bug 24106146.

CVSS3: 3.3
debian
около 10 лет назад

Bouncy Castle in Android before 5.1.1 LMY49F and 6.0 before 2016-01-01 ...

CVSS3: 3.3
github
больше 3 лет назад

Bouncy Castle in Android before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to obtain sensitive information via a crafted application, aka internal bug 24106146.

fstec
около 10 лет назад

Уязвимость операционной системы Android, позволяющая нарушителю получить конфиденциальную информацию

EPSS

Процентиль: 40%
0.00184
Низкий

5.5 Medium

CVSS3