Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

Debian DSA-4233-1 Critical: Bouncy Castle RSA Key Test Risk

debian
Calendar Grey June 22, 2018
Debian Logo
Debian Security Advisory DSA-4233-1 has issued a critical update for the Bouncy Castle library, addressing a vulnerability in RSA key generation that could compromise keys
It was discovered that the low-level interface to the RSA key pair generator of Bouncy Castle (a Java implementation of cryptographic algorithms) could perform less Miller-Rabin pr...

Summary

It was discovered that the low-level interface to the RSA key pair
generator of Bouncy Castle (a Java implementation of cryptographic
algorithms) could perform less Miller-Rabin primality tests than
expected.

For the stable distribution (stretch), this problem has been fixed in
version 1.56-1+deb9u2.

We recommend that you upgrade your bouncycastle packages.

For the detailed security status of bouncycastle please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/bouncycastle

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/



Severity
critical
Lowest
Low
Medium
High
Critical

Package: bouncycastle
CVE ID: CVE-2018-1000180

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here