CVE-2016-1000346

In the Bouncy Castle JCE Provider version 1.55 and earlier the other party DH public key is not fully validated. This can cause issues as invalid keys can be used to reveal details about the other party's private key where static Diffie-Hellman is in use. As of release 1.56 the key parameters are checked on agreement calculation.
Configurations

Configuration 1 (hide)

cpe:2.3:a:bouncycastle:legion-of-the-bouncy-castle-java-crytography-api:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2018-06-04 21:29

Updated : 2023-12-10 12:30


NVD link : CVE-2016-1000346

Mitre link : CVE-2016-1000346

CVE.ORG link : CVE-2016-1000346


JSON object : View

Products Affected

bouncycastle

  • legion-of-the-bouncy-castle-java-crytography-api

debian

  • debian_linux
CWE
CWE-320

Key Management Errors