Vulnerability Description
In the Bouncy Castle JCE Provider version 1.55 and earlier the other party DH public key is not fully validated. This can cause issues as invalid keys can be used to reveal details about the other party's private key where static Diffie-Hellman is in use. As of release 1.56 the key parameters are checked on agreement calculation.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bouncycastle | Bc-Java | <= 1.55 |
| Debian | Debian Linux | 8.0 |
Related Weaknesses (CWE)
References
- https://access.redhat.com/errata/RHSA-2018:2669
- https://access.redhat.com/errata/RHSA-2018:2927
- https://github.com/bcgit/bc-java/commit/1127131c89021612c6eefa26dbe5714c194e7495PatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/07/msg00009.htmlThird Party Advisory
- https://security.netapp.com/advisory/ntap-20181127-0004/
- https://usn.ubuntu.com/3727-1/
- https://www.oracle.com/security-alerts/cpuoct2020.html
- https://access.redhat.com/errata/RHSA-2018:2669
- https://access.redhat.com/errata/RHSA-2018:2927
- https://github.com/bcgit/bc-java/commit/1127131c89021612c6eefa26dbe5714c194e7495PatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/07/msg00009.htmlThird Party Advisory
- https://security.netapp.com/advisory/ntap-20181127-0004/
- https://usn.ubuntu.com/3727-1/
- https://www.oracle.com/security-alerts/cpuoct2020.html
FAQ
What is CVE-2016-1000346?
CVE-2016-1000346 is a vulnerability with a CVSS score of 3.7 (LOW). In the Bouncy Castle JCE Provider version 1.55 and earlier the other party DH public key is not fully validated. This can cause issues as invalid keys can be used to reveal details about the other par...
How severe is CVE-2016-1000346?
CVE-2016-1000346 has been rated LOW with a CVSS base score of 3.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-1000346?
Check the references section above for vendor advisories and patch information. Affected products include: Bouncycastle Bc-Java, Debian Debian Linux.