CVE-2016-1000346

In the Bouncy Castle JCE Provider version 1.55 and earlier the other party DH public key is not fully validated. This can cause issues as invalid keys can be used to reveal details about the other party's private key where static Diffie-Hellman is in use. As of release 1.56 the key parameters are checked on agreement calculation.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:bouncycastle:legion-of-the-bouncy-castle-java-crytography-api:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

Information

Published : 2018-06-04 14:29

Updated : 2020-10-20 15:15


NVD link : CVE-2016-1000346

Mitre link : CVE-2016-1000346


JSON object : View

CWE
CWE-320

Key Management Errors

Advertisement

dedicated server usa

Products Affected

debian

  • debian_linux

bouncycastle

  • legion-of-the-bouncy-castle-java-crytography-api