SB2018060415 - Cryptographic issues in Bouncy Castle
Published: June 4, 2018 Updated: July 5, 2018
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Cryptographic issues (CVE-ID: CVE-2016-1000339)
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability is present in Bouncy Castle JCE Provider due to usage of AESFastEngine that does not provide the sufficient level of secrecy and is prone to side-channel attacks.
Remediation
Install update from vendor's website.