Cryptographic issues in Bouncy Castle for Java - CVE-2016-1000341

 

Cryptographic issues in Bouncy Castle for Java - CVE-2016-1000341

Published: July 5, 2018


Vulnerability identifier: #VU13589
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-1000341
CWE-ID: CWE-310
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists in Bouncy Castle JCE Provider implementation of DSA signature generation process. The attacker with ability to observe timings for the generation of signatures can gain information about the signature's k value and ultimately the private value as well.


Affected software

Bouncy Castle for Java
IBM Sterling File Gateway
Fuse
IBM Cloud Application Performance Management (APM)

How to mitigate CVE-2016-1000341

Install updates from vendor's website.

IBM Sterling File Gateway - addressed in versions 6.0.3.7, 6.1.0.5, 6.1.1.2, 6.1.2.0
Fuse - update to 7.1.0
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.14

External References

Related Security Bulletins