Information disclosure in Bouncy Castle for Java - CVE-2015-7940

 

Information disclosure in Bouncy Castle for Java - CVE-2015-7940

Published: November 30, -0001 / Updated: June 1, 2020


Vulnerability identifier: #VU3403
CSH Severity: Medium
CVSS v4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2015-7940
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due Bouncy Castle Java library before 1.51 does not validate a point is withing the elliptic curve, which makes it easier for remote attackers to obtain private keys via a series of crafted elliptic curve Diffie Hellman (ECDH) key exchanges, aka an "invalid curve attack."


Affected software

Bouncy Castle for Java
Oracle Business Intelligence Enterprise Edition
Fedora
Opensuse
bouncycastle

How to mitigate CVE-2015-7940

Install update from vendor's website.

Bouncy Castle for Java - update to 1.51
bouncycastle - update to 1.50-8.fc22

External References

Related Security Bulletins