BDSA-2018-5235 raised for bouncycastle 1.6.8 · Issue #925 · bcgit/bc-java · GitHub
Skip to content

BDSA-2018-5235 raised for bouncycastle 1.6.8 #925

Description

@erezul

https://fis.blackducksoftware.com/api/vulnerabilities/BDSA-2018-5235/overview
Bouncy Castle contains a weak key-hash message authentication code (HMAC) that is only 16 bits long which can result in hash collisions. This is due to an error within the BKS version 1 keystore (BKS-V1) files and could lead to an attacker being able to affect the integrity of these files.

Note: This issue issue occurs due to functionality that was re-introduced following the fix for CVE-2018-5382 (BDSA-2018-1190).

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions