Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-1000343

Опубликовано: 07 июн. 2018
Источник: redhat
CVSS3: 2.9
EPSS Низкий

Описание

In the Bouncy Castle JCE Provider version 1.55 and earlier the DSA key pair generator generates a weak private key if used with default values. If the JCA key pair generator is not explicitly initialised with DSA parameters, 1.55 and earlier generates a private value assuming a 1024 bit key size. In earlier releases this can be dealt with by explicitly passing parameters to the key pair generator.

Отчет

This issue affects the versions of bouncycastle as shipped with Red Hat Subscription Asset Manager 1.x. Red Hat Product Security has rated this issue as having a security impact of Low. No update is planned for this product at this time. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
JBoss Developer Studio 11bouncycastleNot affected
Red Hat JBoss Data Grid 7bouncycastleNot affected
Red Hat JBoss Data Virtualization 6bouncycastleOut of support scope
Red Hat JBoss Enterprise Application Platform 7bouncycastleNot affected
Red Hat JBoss Fuse 6bouncycastleWill not fix
Red Hat JBoss Fuse Integration Service 2bouncycastleNot affected
Red Hat OpenShift Application RuntimesbouncycastleNot affected
Red Hat Single Sign-On 7bouncycastleNot affected
Red Hat Software Collectionsrh-eclipse46-bouncycastleWill not fix
Red Hat Subscription Asset ManagerbouncycastleWill not fix

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-338
https://bugzilla.redhat.com/show_bug.cgi?id=1588721bouncycastle: DSA key pair generator generates a weak private key by default

EPSS

Процентиль: 72%
0.00726
Низкий

2.9 Low

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 7 лет назад

In the Bouncy Castle JCE Provider version 1.55 and earlier the DSA key pair generator generates a weak private key if used with default values. If the JCA key pair generator is not explicitly initialised with DSA parameters, 1.55 and earlier generates a private value assuming a 1024 bit key size. In earlier releases this can be dealt with by explicitly passing parameters to the key pair generator.

CVSS3: 7.5
nvd
больше 7 лет назад

In the Bouncy Castle JCE Provider version 1.55 and earlier the DSA key pair generator generates a weak private key if used with default values. If the JCA key pair generator is not explicitly initialised with DSA parameters, 1.55 and earlier generates a private value assuming a 1024 bit key size. In earlier releases this can be dealt with by explicitly passing parameters to the key pair generator.

CVSS3: 7.5
debian
больше 7 лет назад

In the Bouncy Castle JCE Provider version 1.55 and earlier the DSA key ...

CVSS3: 7.5
github
больше 7 лет назад

In Bouncy Castle JCE Provider the DSA key pair generator generates a weak private key if used with default values

suse-cvrf
больше 7 лет назад

Security update for bouncycastle

EPSS

Процентиль: 72%
0.00726
Низкий

2.9 Low

CVSS3

Уязвимость CVE-2016-1000343