Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Mageia 6: MGASA-2018-0376 Moderate: BouncyCastle Signature Issue

mageia
Calendar Grey September 21, 2018
Dist Mageia Esm H88
Enhanced Mageia bouncycastle versions address encoding vulnerabilities and safety concerns. Access vital information in this alert immediately.
Updated bouncycastle packages fix security vulnerabilities: Ensure full validation of ASN.1 encoding of signature on verification

Summary

Updated bouncycastle packages fix security vulnerabilities:
Ensure full validation of ASN.1 encoding of signature on verification. It was possible to inject extra elements in the sequence making up the signature and still have it validate, which in some cases may have allowed the introduction of 'invisible' data into a signed structure (CVE-2016-1000338).
Prevent AESEngine key information leak via lookup table accesses (CVE-2016-1000339).
Preventcarry propagation bugs in the implementation of squaring for several raw math classes (CVE-2016-1000340).
DSA signature generation was vulnerable to timing attack. Where timings can be closely observed for the generation of signatures may have allowed an attacker to gain information about the signature's k value and ultimately the private value as well (CVE-2016-1000341).
Ensure that ECDSA does fully validate ASN.1 encoding of signature on verification. It was possible to inject extra elements in the sequence making up the signature and stil...

Read the Full Advisory

References

- https://bugs.mageia.org/show_bug.cgi?id=22197

- https://lists.debian.org/debian-security-announce/2018/msg00162.html

- - - https://www.cve.org/CVERecord?id=CVE-2016-1000338

- https://www.cve.org/CVERecord?id=CVE-2016-1000339

- https://www.cve.org/CVERecord?id=CVE-2016-1000340

- https://www.cve.org/CVERecord?id=CVE-2016-1000341

- https://www.cve.org/CVERecord?id=CVE-2016-1000342

- https://www.cve.org/CVERecord?id=CVE-2016-1000343

- https://www.cve.org/CVERecord?id=CVE-2016-1000344

- https://www.cve.org/CVERecord?id=CVE-2016-1000345

- https://www.cve.org/CVERecord?id=CVE-2016-1000346

- https://www.cve.org/CVERecord?id=CVE-2016-1000352

- https://www.cve.org/CVERecord?id=CVE-2017-13098

- https://www.cve.org/CVERecord?id=CVE-2018-1000180

- https://www.cve.org/CVERecord?id=CVE-2018-1000613

Resolution

SRPMS

- 6/core/bouncycastle-1.60-1.mga6

Publication date: 20 Sep 2018
URL: https://advisories.mageia.org/MGASA-2018-0376.html
Type: security
CVE: CVE-2016-1000338, CVE-2016-1000339, CVE-2016-1000340, CVE-2016-1000341, CVE-2016-1000342, CVE-2016-1000343, CVE-2016-1000344, CVE-2016-1000345, CVE-2016-1000346, CVE-2016-1000352, CVE-2017-13098, CVE-2018-1000180, CVE-2018-1000613

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here