5
CVSSv2

CVE-2016-1000343

Published: 04/06/2018 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

In the Bouncy Castle JCE Provider version 1.55 and previous versions the DSA key pair generator generates a weak private key if used with default values. If the JCA key pair generator is not explicitly initialised with DSA parameters, 1.55 and previous versions generates a private value assuming a 1024 bit key size. In earlier releases this can be dealt with by explicitly passing parameters to the key pair generator.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

bouncycastle legion-of-the-bouncy-castle-java-crytography-api

debian debian linux 8.0

Vendor Advisories

Synopsis Important: Satellite 64 security, bug fix, and enhancement update Type/Severity Security Advisory: Important Topic An update is now available for Red Hat Satellite 64 for RHEL 7Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring ...
Synopsis Important: Fuse 71 security update Type/Severity Security Advisory: Important Topic An update is now available for Red Hat FuseRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed s ...
Several security issues were fixed in Bouncy Castle ...
In the Bouncy Castle JCE Provider version 155 and earlier the DSA key pair generator generates a weak private key if used with default values If the JCA key pair generator is not explicitly initialised with DSA parameters, 155 and earlier generates a private value assuming a 1024 bit key size In earlier releases this can be dealt with by explic ...

Github Repositories

Java SDK for CyberSource Simple Order API

CyberSource Simple Order API for Java Package Managers Maven To install the cybersource-sdk-java from central repository, add dependency to your application pomxml as below <dependency> <groupId>comcybersource</groupId> <artifactId>cybersource-sdk-java</artifactId> <version>6213&