Alerts This Week
Warning Icon 1 1,149
Alerts This Week
Warning Icon 1 1,149

Debian 8 LTS: DLA-1418-1 Moderate: Bouncycastle Security Issues

debian lts
Calendar Grey July 7, 2018
Dist Debian Esm H88
Numerous security flaws identified in Bouncy Castle necessitate prompt software upgrades and a reassessment of cryptographic protocols.
Several security vulnerabilities were found in Bouncy Castle, a Java implementation of cryptographic algorithms

Summary

CVE-2016-1000339
Previously the primary engine class used for AES was AESFastEngine.
Due to the highly table driven approach used in the algorithm it
turns out that if the data channel on the CPU can be monitored the
lookup table accesses are sufficient to leak information on the AES
key being used. There was also a leak in AESEngine although it was
substantially less. AESEngine has been modified to remove any signs
of leakage and is now the primary AES class for the BC JCE provider.
Use of AESFastEngine is now only recommended where otherwise deemed
appropriate.

CVE-2016-1000341
DSA signature generation is vulnerable to timing attack. Where
timings can be closely observed for the generation of signatures,
the lack of blinding may allow an attacker to gain information about
the signature's k value and ultimately the private value as well.

CVE-2016-1000342
ECDSA does not fully validate ASN.1 encoding of signature on

Read the Full Advisory


Package: bouncycastle
Version: 1.49+dfsg-3+deb8u3
CVE ID: CVE-2016-1000338 CVE-2016-1000339 CVE-2016-1000341

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here