4.3
CVSSv2

CVE-2016-1000341

Published: 04/06/2018 Updated: 20/10/2020
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.9 | Impact Score: 3.6 | Exploitability Score: 2.2
VMScore: 384
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

In the Bouncy Castle JCE Provider version 1.55 and previous versions DSA signature generation is vulnerable to timing attack. Where timings can be closely observed for the generation of signatures, the lack of blinding in 1.55, or earlier, may allow an malicious user to gain information about the signature's k value and ultimately the private value as well.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

bouncycastle legion-of-the-bouncy-castle-java-crytography-api

debian debian linux 8.0

Vendor Advisories

Synopsis Important: Satellite 64 security, bug fix, and enhancement update Type/Severity Security Advisory: Important Topic An update is now available for Red Hat Satellite 64 for RHEL 7Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring ...
Synopsis Important: Fuse 71 security update Type/Severity Security Advisory: Important Topic An update is now available for Red Hat FuseRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed s ...
Several security issues were fixed in Bouncy Castle ...
In the Bouncy Castle JCE Provider version 155 and earlier DSA signature generation is vulnerable to timing attack Where timings can be closely observed for the generation of signatures, the lack of blinding in 155, or earlier, may allow an attacker to gain information about the signature's k value and ultimately the private value as well ...