cbcvebase.
CVE-2016-1000346
published 2018-06-04

CVE-2016-1000346: In the Bouncy Castle JCE Provider version 1.55 and earlier the other party DH public key is not fully validated. This can cause issues as invalid keys can be…

PriorityP414low3.7CVSS 3.0
AVNACHPRNUINSUCLINAN
EPSS
2.30%
81.4th percentile
In the Bouncy Castle JCE Provider version 1.55 and earlier the other party DH public key is not fully validated. This can cause issues as invalid keys can be used to reveal details about the other party's private key where static Diffie-Hellman is in use. As of release 1.56 the key parameters are checked on agreement calculation.

Affected

3 ranges
VendorProductVersion rangeFixed in
bouncycastlebc-java<= 1.55
debianbouncycastle< bouncycastle 1.56-1 (bookworm)bouncycastle 1.56-1 (bookworm)
debiandebian_linux

CVSS provenance

nvdv3.03.7LOWCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv3.7LOW
vendor_debian3.7LOW
vendor_redhat3.7LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.