CVE-2015-7940
published 2015-11-09CVE-2015-7940: The Bouncy Castle Java library before 1.51 does not validate a point is withing the elliptic curve, which makes it easier for remote attackers to obtain…
PriorityP428medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
4.82%
91.0th percentile
The Bouncy Castle Java library before 1.51 does not validate a point is withing the elliptic curve, which makes it easier for remote attackers to obtain private keys via a series of crafted elliptic curve Diffie Hellman (ECDH) key exchanges, aka an "invalid curve attack."
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| bouncycastle | bouncy_castle_crypto_package | <= 1.50 | — |
| debian | bouncycastle | < bouncycastle 1.51-1 (bookworm) | bouncycastle 1.51-1 (bookworm) |
| opensuse | leap | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| oracle | application_testing_suite | — | — |
| oracle | application_testing_suite | — | — |
| oracle | application_testing_suite | — | — |
| oracle | enterprise_manager_ops_center | — | — |
| oracle | enterprise_manager_ops_center | — | — |
| oracle | peoplesoft_enterprise_peopletools | — | — |
| oracle | peoplesoft_enterprise_peopletools | — | — |
| oracle | virtual_desktop_infrastructure | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv5.0MEDIUM
vendor_oracle7.5MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Moderate severity vulnerability that affects org.bouncycastle:bcprov-jdk14 and org.bouncycastle:bcprov-jdk15
osv·2018-10-17
CVE-2015-7940 [MEDIUM] Moderate severity vulnerability that affects org.bouncycastle:bcprov-jdk14 and org.bouncycastle:bcprov-jdk15
Moderate severity vulnerability that affects org.bouncycastle:bcprov-jdk14 and org.bouncycastle:bcprov-jdk15
The Bouncy Castle Java library before 1.51 does not validate a point is withing the elliptic curve, which makes it easier for remote attackers to obtain private keys via a series of crafted elliptic curve Diffie Hellman (ECDH) key exchanges, aka an "invalid curve attack."
GHSA
Moderate severity vulnerability that affects org.bouncycastle:bcprov-jdk14 and org.bouncycastle:bcprov-jdk15
ghsa·2018-10-17
CVE-2015-7940 [MEDIUM] CWE-200 Moderate severity vulnerability that affects org.bouncycastle:bcprov-jdk14 and org.bouncycastle:bcprov-jdk15
Moderate severity vulnerability that affects org.bouncycastle:bcprov-jdk14 and org.bouncycastle:bcprov-jdk15
The Bouncy Castle Java library before 1.51 does not validate a point is withing the elliptic curve, which makes it easier for remote attackers to obtain private keys via a series of crafted elliptic curve Diffie Hellman (ECDH) key exchanges, aka an "invalid curve attack."
OSV
CVE-2015-7940: The Bouncy Castle Java library before 1
osv·2015-11-09·CVSS 5.0
CVE-2015-7940 [MEDIUM] CVE-2015-7940: The Bouncy Castle Java library before 1
The Bouncy Castle Java library before 1.51 does not validate a point is withing the elliptic curve, which makes it easier for remote attackers to obtain private keys via a series of crafted elliptic curve Diffie Hellman (ECDH) key exchanges, aka an "invalid curve attack."
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Installation (Bouncy Castle Java Library) — CVE-2015-7940
vendor_oracle·2020-04-15·CVSS 7.5
CVE-2015-7940 [MEDIUM] Oracle Oracle Fusion Middleware Risk Matrix: Installation (Bouncy Castle Java Library) — CVE-2015-7940
Oracle Oracle Fusion Middleware Risk Matrix: Installation (Bouncy Castle Java Library) vulnerability
CVE: CVE-2015-7940
CVSS: 7.5
Protocol: HTTPS
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2020 (APR 2020)
Ubuntu
Bouncy Castle vulnerabilities
vendor_ubuntu·2018-08-01
CVE-2015-6644 Bouncy Castle vulnerabilities
Title: Bouncy Castle vulnerabilities
Summary: Several security issues were fixed in Bouncy Castle.
It was discovered that Bouncy Castle incorrectly handled certain crypto
algorithms. A remote attacker could possibly use these issues to obtain
sensitive information, including private keys.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
bouncycastle: Invalid curve attack allowing to extract private keys
vendor_redhat·2015-09-14·CVSS 5.0
CVE-2015-7940 [MEDIUM] CWE-358 bouncycastle: Invalid curve attack allowing to extract private keys
bouncycastle: Invalid curve attack allowing to extract private keys
The Bouncy Castle Java library before 1.51 does not validate a point is withing the elliptic curve, which makes it easier for remote attackers to obtain private keys via a series of crafted elliptic curve Diffie Hellman (ECDH) key exchanges, aka an "invalid curve attack."
It was found that bouncycastle is vulnerable to an invalid curve attack. An attacker could extract private keys used in elliptic curve cryptography with a few thousand queries.
Package: fabric8 (Red Hat JBoss A-MQ 6) - Affected
Package: fabric8 (Red Hat JBoss Fuse 6) - Affected
Package: bouncycastle (Red Hat Satellite 6) - Will not fix
Package: bouncycastle (Red Hat Subscription Asset Manager) - Will not fix
Debian
CVE-2015-7940: bouncycastle - The Bouncy Castle Java library before 1.51 does not validate a point is withing ...
vendor_debian·2015·CVSS 5.0
CVE-2015-7940 [MEDIUM] CVE-2015-7940: bouncycastle - The Bouncy Castle Java library before 1.51 does not validate a point is withing ...
The Bouncy Castle Java library before 1.51 does not validate a point is withing the elliptic curve, which makes it easier for remote attackers to obtain private keys via a series of crafted elliptic curve Diffie Hellman (ECDH) key exchanges, aka an "invalid curve attack."
Scope: local
bookworm: resolved (fixed in 1.51-1)
bullseye: resolved (fixed in 1.51-1)
forky: resolved (fixed in 1.51-1)
sid: resolved (fixed in 1.51-1)
trixie: resolved (fixed in 1.51-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-7940 bouncycastle: Invalid curve attack allowing to extract private keys [fedora-all]
bugzilla·2015-11-03·CVSS 5.0
CVE-2015-7940 [MEDIUM] CVE-2015-7940 bouncycastle: Invalid curve attack allowing to extract private keys [fedora-all]
CVE-2015-7940 bouncycastle: Invalid curve attack allowing to extract private keys [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple suppo
Bugzilla
CVE-2015-7940 bouncycastle: Invalid curve attack allowing to extract private keys [epel-all]
bugzilla·2015-11-03·CVSS 5.0
CVE-2015-7940 [MEDIUM] CVE-2015-7940 bouncycastle: Invalid curve attack allowing to extract private keys [epel-all]
CVE-2015-7940 bouncycastle: Invalid curve attack allowing to extract private keys [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple su
Bugzilla
CVE-2015-7940 bouncycastle: Invalid curve attack allowing to extract private keys
bugzilla·2015-10-29·CVSS 5.0
CVE-2015-7940 [MEDIUM] CVE-2015-7940 bouncycastle: Invalid curve attack allowing to extract private keys
CVE-2015-7940 bouncycastle: Invalid curve attack allowing to extract private keys
A vulnerability in bouncycastle implementation was found, allowing to perform invalid curve attack. The attack allows to extract private keys used in elliptic curve cryptography with a few thousand queries.
Upstream patches:
https://github.com/bcgit/bc-java/commit/5cb2f0578e6ec8f0d67e59d05d8c4704d8e05f83
https://github.com/bcgit/bc-java/commit/e25e94a046a6934819133886439984e2fecb2b04
CVE assignment:
http://seclists.org/oss-sec/2015/q4/131
Detailed info about the attack:
http://web-in-security.blogspot.ca/2015/09/practical-invalid-curve-attacks.html
Discussion:
Seem affected only in Fedora 21 and 22 (1.50).
For Fedora 23 and 24 use bouncycastle 1.52.
---
Subscription Asset Manager and Satellite 6 bo
Bugzilla
CVE-2014-7940 ICU: uninitialized value use in the collation component
bugzilla·2015-01-23·CVSS 7.5
CVE-2014-7940 [HIGH] CVE-2014-7940 ICU: uninitialized value use in the collation component
CVE-2014-7940 ICU: uninitialized value use in the collation component
An unspecified uninitialized-value flaw was found in the ICU component of the Chromium browser.
External References:
http://googlechromereleases.blogspot.com/2015/01/stable-update.html
Discussion:
Google Chrome bug is:
https://code.google.com/p/chromium/issues/detail?id=433866
However, the bug is currently not public. The following commits can be identified using the bug id:
https://chromium.googlesource.com/chromium/deps/icu/+/866ff696e9022a6000afbab516fba62cfa306075
https://chromium.googlesource.com/chromium/deps/icu/+/a626a75aad2675254073366fcaa9465dacf17100
Chrome README includes the following information about ICU upstream status of this issue:
- No upstream bug filed because the upstream code was complete
http://lists.fedoraproject.org/pipermail/package-announce/2016-January/174915.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-11/msg00012.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2035.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2036.htmlhttp://web-in-security.blogspot.ca/2015/09/practical-invalid-curve-attacks.htmlhttp://www.debian.org/security/2015/dsa-3417http://www.openwall.com/lists/oss-security/2015/10/22/7http://www.openwall.com/lists/oss-security/2015/10/22/9http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.htmlhttp://www.securityfocus.com/bid/79091http://www.securitytracker.com/id/1037036http://www.securitytracker.com/id/1037046http://www.securitytracker.com/id/1037053https://usn.ubuntu.com/3727-1/https://www.oracle.com/security-alerts/cpuapr2020.htmlhttps://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-January/174915.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-11/msg00012.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2035.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2036.htmlhttp://web-in-security.blogspot.ca/2015/09/practical-invalid-curve-attacks.htmlhttp://www.debian.org/security/2015/dsa-3417http://www.openwall.com/lists/oss-security/2015/10/22/7http://www.openwall.com/lists/oss-security/2015/10/22/9http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.htmlhttp://www.securityfocus.com/bid/79091http://www.securitytracker.com/id/1037036http://www.securitytracker.com/id/1037046http://www.securitytracker.com/id/1037053https://usn.ubuntu.com/3727-1/https://www.oracle.com/security-alerts/cpuapr2020.htmlhttps://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html
2015-11-09
Published