CVE Vulnerabilities

CVE-2016-1000341

Published: Jun 04, 2018 | Modified: Oct 20, 2020
CVSS 3.x
5.9
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

In the Bouncy Castle JCE Provider version 1.55 and earlier DSA signature generation is vulnerable to timing attack. Where timings can be closely observed for the generation of signatures, the lack of blinding in 1.55, or earlier, may allow an attacker to gain information about the signatures k value and ultimately the private value as well.

Affected Software

Name Vendor Start Version End Version
Legion-of-the-bouncy-castle-java-crytography-api Bouncycastle * 1.55 (including)

References