PT-2018-4634 · Bouncy Castle+1 · Bouncy Castle Jce Provider+1
CVE-2016-1000340
·
Publicado
2018-06-04
·
Atualizado
2025-05-12
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Bouncy Castle JCE Provider versions 1.51 through 1.55
Description
A carry propagation bug was introduced in the implementation of squaring for several raw math classes, which are used by custom elliptic curve implementations. This bug could have led to rare spurious calculations for elliptic curve scalar multiplications. However, such errors would have been detected with high probability by the output validation for scalar multipliers.
Recommendations
For Bouncy Castle JCE Provider versions 1.51 through 1.55, update to a version that includes the fix for the carry propagation bug in the raw math classes.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Bouncy Castle Jce Provider
Suse