CVE-2016-1000340

CWE-19CWE-68210 documents7 sources
Severity
7.5HIGH
EPSS
0.4%
top 39.43%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 4
Latest updateOct 17

Description

In the Bouncy Castle JCE Provider versions 1.51 to 1.55, a carry propagation bug was introduced in the implementation of squaring for several raw math classes have been fixed (org.bouncycastle.math.raw.Nat???). These classes are used by our custom elliptic curve implementations (org.bouncycastle.math.ec.custom.**), so there was the possibility of rare (in general usage) spurious calculations for elliptic curve scalar multiplications. Such errors would have been detected with high probability by

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages5 packages

Mavenorg.bouncycastle:bcprov-jdk141.511.56
Mavenorg.bouncycastle:bcprov-jdk151.511.56
Mavenorg.bouncycastle:bcprov-jdk15on1.511.56
Debianbouncycastle< 1.56-1+3
NVDbouncycastle/bc-java1.511.55

Patches

🔴Vulnerability Details

4
GHSA
The Bouncy Castle JCE Provider carry a propagation bug2018-10-17
OSV
The Bouncy Castle JCE Provider carry a propagation bug2018-10-17
CVEList
CVE-2016-1000340: In the Bouncy Castle JCE Provider versions 12018-06-04
OSV
CVE-2016-1000340: In the Bouncy Castle JCE Provider versions 12018-06-04

📋Vendor Advisories

2
Red Hat
bouncycastle: Carry propagation bug in math.raw.Nat??? class2018-06-07
Debian
CVE-2016-1000340: bouncycastle - In the Bouncy Castle JCE Provider versions 1.51 to 1.55, a carry propagation bug...2016

💬Community

3
Bugzilla
CVE-2016-1000340 bouncycastle: Carry propagation bug in math.raw.Nat??? class [epel-all]2018-06-07
Bugzilla
CVE-2016-1000340 bouncycastle: Carry propagation bug in math.raw.Nat??? class [fedora-all]2018-06-07
Bugzilla
CVE-2016-1000340 bouncycastle: Carry propagation bug in math.raw.Nat??? class2018-06-07
CVE-2016-1000340 (HIGH CVSS 7.5) | In the Bouncy Castle JCE Provider v | cvebase.io