CVE-2015-6644
published 2016-01-06CVE-2015-6644: Bouncy Castle in Android before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to obtain sensitive information via a crafted application, aka internal…
PriorityP49low3.3CVSS 3.0
AVLACLPRNUIRSUCLINAN
EPSS
0.93%
56.8th percentile
Bouncy Castle in Android before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to obtain sensitive information via a crafted application, aka internal bug 24106146.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | bouncycastle | < bouncycastle 1.54-1 (bookworm) | bouncycastle 1.54-1 (bookworm) |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — |
CVSS provenance
nvdv3.03.3LOWCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv3.3LOW
vendor_debian3.3LOW
vendor_redhat3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-x38m-968w-w2xq: Bouncy Castle in Android before 5
ghsa_unreviewed·2022-05-14
CVE-2015-6644 [MEDIUM] CWE-200 GHSA-x38m-968w-w2xq: Bouncy Castle in Android before 5
Bouncy Castle in Android before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to obtain sensitive information via a crafted application, aka internal bug 24106146.
OSV
CVE-2015-6644: Bouncy Castle in Android before 5
osv·2016-01-06·CVSS 3.3
CVE-2015-6644 [LOW] CVE-2015-6644: Bouncy Castle in Android before 5
Bouncy Castle in Android before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to obtain sensitive information via a crafted application, aka internal bug 24106146.
Ubuntu
Bouncy Castle vulnerabilities
vendor_ubuntu·2018-08-01
CVE-2015-6644 Bouncy Castle vulnerabilities
Title: Bouncy Castle vulnerabilities
Summary: Several security issues were fixed in Bouncy Castle.
It was discovered that Bouncy Castle incorrectly handled certain crypto
algorithms. A remote attacker could possibly use these issues to obtain
sensitive information, including private keys.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
bouncycastle: Information disclosure in GCMBlockCipher
vendor_redhat·2016-01-01·CVSS 3.3
CVE-2015-6644 [LOW] CWE-200 bouncycastle: Information disclosure in GCMBlockCipher
bouncycastle: Information disclosure in GCMBlockCipher
Bouncy Castle in Android before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to obtain sensitive information via a crafted application, aka internal bug 24106146.
It was found that an information disclosure flaw in Bouncy Castle could enable a local malicious application to gain access to user's private information.
Package: fabric8 (Red Hat JBoss A-MQ 6) - Affected
Package: bouncycastle (Red Hat Subscription Asset Manager) - Will not fix
Android
CVE-2015-6644: Android Security Bulletin 2016-01-01
CVE: CVE-2015-6644
Severity: MEDIUM
Affected AOSP versions: 4
vendor_android·2016-01-01·CVSS 3.3
CVE-2015-6644 [LOW] CVE-2015-6644: Android Security Bulletin 2016-01-01
CVE: CVE-2015-6644
Severity: MEDIUM
Affected AOSP versions: 4
Android Security Bulletin 2016-01-01
CVE: CVE-2015-6644
Severity: MEDIUM
Affected AOSP versions: 4.4.4, 5.0, 5.1.1, 6.0, 6.0.1
Debian
CVE-2015-6644: bouncycastle - Bouncy Castle in Android before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows at...
vendor_debian·2015·CVSS 3.3
CVE-2015-6644 [LOW] CVE-2015-6644: bouncycastle - Bouncy Castle in Android before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows at...
Bouncy Castle in Android before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to obtain sensitive information via a crafted application, aka internal bug 24106146.
Scope: local
bookworm: resolved (fixed in 1.54-1)
bullseye: resolved (fixed in 1.54-1)
forky: resolved (fixed in 1.54-1)
sid: resolved (fixed in 1.54-1)
trixie: resolved (fixed in 1.54-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-6644 bouncycastle: Information disclosure in GCMBlockCipher
bugzilla·2017-04-20·CVSS 3.3
CVE-2015-6644 [LOW] CVE-2015-6644 bouncycastle: Information disclosure in GCMBlockCipher
CVE-2015-6644 bouncycastle: Information disclosure in GCMBlockCipher
An information disclosure vulnerability in Bouncy Castle could enable a local malicious application to gain access to user’s private information.
Upstream bug:
https://github.com/bcgit/bc-java/issues/177
References:
https://source.android.com/security/bulletin/2016-01-01#information_disclosure_vulnerability_in_bouncy_castle
Discussion:
Created bouncycastle tracking bugs for this issue:
Affects: epel-all [bug 1444025]
Affects: fedora-24 [bug 1444024]
---
JBoss fuse ships bouncycastle version 1.54 in fabric8, camel and karaf container.
To have the fix for this particular CVE users should update to version 1.56 or later.
---
This issue has been addressed in the following products:
Red Hat JBoss Fuse
Via RHSA-20
Bugzilla
CVE-2015-6644 bouncycastle: Information disclosure in GCMBlockCipher [epel-all]
bugzilla·2017-04-20·CVSS 3.3
CVE-2015-6644 [LOW] CVE-2015-6644 bouncycastle: Information disclosure in GCMBlockCipher [epel-all]
CVE-2015-6644 bouncycastle: Information disclosure in GCMBlockCipher [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions
Bugzilla
CVE-2015-6644 bouncycastle: Information disclosure in GCMBlockCipher [fedora-24]
bugzilla·2017-04-20·CVSS 3.3
CVE-2015-6644 [LOW] CVE-2015-6644 bouncycastle: Information disclosure in GCMBlockCipher [fedora-24]
CVE-2015-6644 bouncycastle: Information disclosure in GCMBlockCipher [fedora-24]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-24.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the following template to for the
http://source.android.com/security/bulletin/2016-01-01.htmlhttp://www.debian.org/security/2017/dsa-3829http://www.securityfocus.com/bid/79865http://www.securitytracker.com/id/1034592https://access.redhat.com/errata/RHSA-2017:1832https://access.redhat.com/errata/RHSA-2017:2808https://access.redhat.com/errata/RHSA-2017:2809https://access.redhat.com/errata/RHSA-2017:2810https://access.redhat.com/errata/RHSA-2017:2811https://access.redhat.com/errata/RHSA-2018:2927https://usn.ubuntu.com/3727-1/http://source.android.com/security/bulletin/2016-01-01.htmlhttp://www.debian.org/security/2017/dsa-3829http://www.securityfocus.com/bid/79865http://www.securitytracker.com/id/1034592https://access.redhat.com/errata/RHSA-2017:1832https://access.redhat.com/errata/RHSA-2017:2808https://access.redhat.com/errata/RHSA-2017:2809https://access.redhat.com/errata/RHSA-2017:2810https://access.redhat.com/errata/RHSA-2017:2811https://access.redhat.com/errata/RHSA-2018:2927https://usn.ubuntu.com/3727-1/
2016-01-06
Published