Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-7940

Опубликовано: 14 сент. 2015
Источник: redhat
CVSS3: 3.7
CVSS2: 4.3
EPSS Низкий

Описание

The Bouncy Castle Java library before 1.51 does not validate a point is withing the elliptic curve, which makes it easier for remote attackers to obtain private keys via a series of crafted elliptic curve Diffie Hellman (ECDH) key exchanges, aka an "invalid curve attack."

It was found that bouncycastle is vulnerable to an invalid curve attack. An attacker could extract private keys used in elliptic curve cryptography with a few thousand queries.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss A-MQ 6fabric8Affected
Red Hat JBoss Fuse 6fabric8Affected
Red Hat Satellite 6bouncycastleWill not fix
Red Hat Subscription Asset ManagerbouncycastleWill not fix
Red Hat JBoss A-MQ 6.3FixedRHSA-2016:203606.10.2016
Red Hat JBoss Fuse 6.3FixedRHSA-2016:203506.10.2016

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-358
https://bugzilla.redhat.com/show_bug.cgi?id=1276272bouncycastle: Invalid curve attack allowing to extract private keys

EPSS

Процентиль: 77%
0.01019
Низкий

3.7 Low

CVSS3

4.3 Medium

CVSS2

Связанные уязвимости

ubuntu
около 10 лет назад

The Bouncy Castle Java library before 1.51 does not validate a point is withing the elliptic curve, which makes it easier for remote attackers to obtain private keys via a series of crafted elliptic curve Diffie Hellman (ECDH) key exchanges, aka an "invalid curve attack."

nvd
около 10 лет назад

The Bouncy Castle Java library before 1.51 does not validate a point is withing the elliptic curve, which makes it easier for remote attackers to obtain private keys via a series of crafted elliptic curve Diffie Hellman (ECDH) key exchanges, aka an "invalid curve attack."

debian
около 10 лет назад

The Bouncy Castle Java library before 1.51 does not validate a point i ...

suse-cvrf
больше 10 лет назад

Security update for bouncycastle

github
больше 7 лет назад

Moderate severity vulnerability that affects org.bouncycastle:bcprov-jdk14 and org.bouncycastle:bcprov-jdk15

EPSS

Процентиль: 77%
0.01019
Низкий

3.7 Low

CVSS3

4.3 Medium

CVSS2