Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-1000613

Опубликовано: 03 мар. 2018
Источник: redhat
CVSS3: 4.9
EPSS Низкий

Описание

Legion of the Bouncy Castle Legion of the Bouncy Castle Java Cryptography APIs 1.58 up to but not including 1.60 contains a CWE-470: Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in XMSS/XMSS^MT private key deserialization that can result in Deserializing an XMSS/XMSS^MT private key can result in the execution of unexpected code. This attack appear to be exploitable via A handcrafted private key can include references to unexpected classes which will be picked up from the class path for the executing application. This vulnerability appears to have been fixed in 1.60 and later.

Отчет

The XMSS/XMSS^MT algorithms were first introduced in upstream bouncycastle version 1.57. Versions prior to this, that have not had the new algorithms back-ported, are not affected.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
JBoss Developer Studio 11bouncycastleNot affected
Red Hat Fuse 7jclouds-bouncycastleNot affected
Red Hat JBoss Data Virtualization 6bouncycastleWill not fix
Red Hat JBoss Enterprise Application Platform 7bouncycastleNot affected
Red Hat JBoss Fuse 6jclouds-bouncycastleNot affected
Red Hat Satellite 6bouncycastleNot affected
Red Hat Software Collectionsrh-eclipse46-bouncycastleNot affected
Red Hat Subscription Asset ManagerbouncycastleNot affected
Red Hat Virtualization 4eap7-bouncycastleNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-470
https://bugzilla.redhat.com/show_bug.cgi?id=1601096bouncycastle: lack of class checking in deserialization of XMSS/XMSS^MT private keys with BDS state information

EPSS

Процентиль: 88%
0.04043
Низкий

4.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 7 лет назад

Legion of the Bouncy Castle Legion of the Bouncy Castle Java Cryptography APIs 1.58 up to but not including 1.60 contains a CWE-470: Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in XMSS/XMSS^MT private key deserialization that can result in Deserializing an XMSS/XMSS^MT private key can result in the execution of unexpected code. This attack appear to be exploitable via A handcrafted private key can include references to unexpected classes which will be picked up from the class path for the executing application. This vulnerability appears to have been fixed in 1.60 and later.

CVSS3: 9.8
nvd
больше 7 лет назад

Legion of the Bouncy Castle Legion of the Bouncy Castle Java Cryptography APIs 1.58 up to but not including 1.60 contains a CWE-470: Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in XMSS/XMSS^MT private key deserialization that can result in Deserializing an XMSS/XMSS^MT private key can result in the execution of unexpected code. This attack appear to be exploitable via A handcrafted private key can include references to unexpected classes which will be picked up from the class path for the executing application. This vulnerability appears to have been fixed in 1.60 and later.

CVSS3: 9.8
debian
больше 7 лет назад

Legion of the Bouncy Castle Legion of the Bouncy Castle Java Cryptogra ...

suse-cvrf
больше 7 лет назад

Security update for bouncycastle

CVSS3: 9.8
github
больше 7 лет назад

Deserialization of Untrusted Data in Bouncy castle

EPSS

Процентиль: 88%
0.04043
Низкий

4.9 Medium

CVSS3