CVE-2018-1000180
published 2018-06-05CVE-2018-1000180: Bouncy Castle BC 1.54 - 1.59, BC-FJA 1.0.0, BC-FJA 1.0.1 and earlier have a flaw in the Low-level interface to RSA key pair generator, specifically RSA Key…
PriorityP342high7.5CVSS 3.0
AVNACLPRNUINSUCHINAN
EPSS
3.62%
88.3th percentile
Bouncy Castle BC 1.54 - 1.59, BC-FJA 1.0.0, BC-FJA 1.0.1 and earlier have a flaw in the Low-level interface to RSA key pair generator, specifically RSA Key Pairs generated in low-level API with added certainty may have less M-R tests than expected. This appears to be fixed in versions BC 1.60 beta 4 and later, BC-FJA 1.0.2 and later.
Affected
29 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| bouncycastle | bc-java | 1.54 – 1.59 | — |
| bouncycastle | fips_java_api | <= 1.0.1 | — |
| debian | bouncycastle | < bouncycastle 1.59-2 (bookworm) | bouncycastle 1.59-2 (bookworm) |
| debian | debian_linux | — | — |
| oracle | api_gateway | — | — |
| oracle | business_process_management_suite | — | — |
| oracle | business_process_management_suite | — | — |
| oracle | business_process_management_suite | — | — |
| oracle | business_transaction_management | — | — |
| oracle | communications_application_session_controller | — | — |
| oracle | communications_application_session_controller | — | — |
| oracle | communications_converged_application_server | < 7.0.0.1 | 7.0.0.1 |
| oracle | communications_webrtc_session_controller | < 7.2 | 7.2 |
| oracle | enterprise_repository | — | — |
| oracle | managed_file_transfer | — | — |
| oracle | managed_file_transfer | — | — |
| oracle | peoplesoft_enterprise_peopletools | — | — |
| oracle | peoplesoft_enterprise_peopletools | — | — |
| oracle | peoplesoft_enterprise_peopletools | — | — |
| oracle | retail_convenience_and_fuel_pos_software | — | — |
| oracle | retail_xstore_point_of_service | — | — |
| oracle | retail_xstore_point_of_service | — | — |
| oracle | soa_suite | — | — |
| oracle | soa_suite | — | — |
| oracle | webcenter_portal | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv7.5HIGH
vendor_debian7.5HIGH
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Security Subsystem (Bouncy Castle Java Library) — CVE-2018-1000180
vendor_oracle·2021-04-15·CVSS 7.5
CVE-2018-1000180 [HIGH] Oracle Oracle Fusion Middleware Risk Matrix: Security Subsystem (Bouncy Castle Java Library) — CVE-2018-1000180
Oracle Oracle Fusion Middleware Risk Matrix: Security Subsystem (Bouncy Castle Java Library) vulnerability
CVE: CVE-2018-1000180
CVSS: 7.5
Protocol: HTTPS
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2021 (APR 2021)
Oracle
Oracle Oracle Communications Applications Risk Matrix: IDIH Visualization (Bouncy Castle Java Library) — CVE-2018-1000180
vendor_oracle·2020-04-15·CVSS 7.5
CVE-2018-1000180 [HIGH] Oracle Oracle Communications Applications Risk Matrix: IDIH Visualization (Bouncy Castle Java Library) — CVE-2018-1000180
Oracle Oracle Communications Applications Risk Matrix: IDIH Visualization (Bouncy Castle Java Library) vulnerability
CVE: CVE-2018-1000180
CVSS: 7.5
Protocol: TLS
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2020 (APR 2020)
Red Hat
bouncycastle: flaw in the low-level interface to RSA key pair generator
vendor_redhat·2018-04-18·CVSS 7.5
CVE-2018-1000180 [HIGH] CWE-325 bouncycastle: flaw in the low-level interface to RSA key pair generator
bouncycastle: flaw in the low-level interface to RSA key pair generator
Bouncy Castle BC 1.54 - 1.59, BC-FJA 1.0.0, BC-FJA 1.0.1 and earlier have a flaw in the Low-level interface to RSA key pair generator, specifically RSA Key Pairs generated in low-level API with added certainty may have less M-R tests than expected. This appears to be fixed in versions BC 1.60 beta 4 and later, BC-FJA 1.0.2 and later.
A vulnerability was found in BouncyCastle. The number of iterations of the Miller-Rabin primality test was incorrectly calculated (according to FIPS 186-4 C.3). Under some circumstances, this could lead to the generation of weak RSA key pairs.
Statement: This issue affects the versions of bouncycastle as shipped with Red Hat Subscription Asset Manager 1.x. Red Hat Product Security has r
Debian
CVE-2018-1000180: bouncycastle - Bouncy Castle BC 1.54 - 1.59, BC-FJA 1.0.0, BC-FJA 1.0.1 and earlier have a flaw...
vendor_debian·2018·CVSS 7.5
CVE-2018-1000180 [HIGH] CVE-2018-1000180: bouncycastle - Bouncy Castle BC 1.54 - 1.59, BC-FJA 1.0.0, BC-FJA 1.0.1 and earlier have a flaw...
Bouncy Castle BC 1.54 - 1.59, BC-FJA 1.0.0, BC-FJA 1.0.1 and earlier have a flaw in the Low-level interface to RSA key pair generator, specifically RSA Key Pairs generated in low-level API with added certainty may have less M-R tests than expected. This appears to be fixed in versions BC 1.60 beta 4 and later, BC-FJA 1.0.2 and later.
Scope: local
bookworm: resolved (fixed in 1.59-2)
bullseye: resolved (fixed in 1.59-2)
forky: resolved (fixed in 1.59-2)
sid: resolved (fixed in 1.59-2)
trixie: resolved (fixed in 1.59-2)
OSV
Bouncy Castle has a flaw in the Low-level interface to RSA key pair generator
osv·2018-10-16
CVE-2018-1000180 [HIGH] Bouncy Castle has a flaw in the Low-level interface to RSA key pair generator
Bouncy Castle has a flaw in the Low-level interface to RSA key pair generator
Bouncy Castle BC 1.54 - 1.59, BC-FJA 1.0.0, BC-FJA 1.0.1 and earlier have a flaw in the Low-level interface to RSA key pair generator, specifically RSA Key Pairs generated in low-level API with added certainty may have less M-R tests than expected. This appears to be fixed in versions BC 1.60 beta 4 and later, BC-FJA 1.0.2 and later.
GHSA
Bouncy Castle has a flaw in the Low-level interface to RSA key pair generator
ghsa·2018-10-16
CVE-2018-1000180 [HIGH] CWE-327 Bouncy Castle has a flaw in the Low-level interface to RSA key pair generator
Bouncy Castle has a flaw in the Low-level interface to RSA key pair generator
Bouncy Castle BC 1.54 - 1.59, BC-FJA 1.0.0, BC-FJA 1.0.1 and earlier have a flaw in the Low-level interface to RSA key pair generator, specifically RSA Key Pairs generated in low-level API with added certainty may have less M-R tests than expected. This appears to be fixed in versions BC 1.60 beta 4 and later, BC-FJA 1.0.2 and later.
OSV
CVE-2018-1000180: Bouncy Castle BC 1
osv·2018-06-05·CVSS 7.5
CVE-2018-1000180 [HIGH] CVE-2018-1000180: Bouncy Castle BC 1
Bouncy Castle BC 1.54 - 1.59, BC-FJA 1.0.0, BC-FJA 1.0.1 and earlier have a flaw in the Low-level interface to RSA key pair generator, specifically RSA Key Pairs generated in low-level API with added certainty may have less M-R tests than expected. This appears to be fixed in versions BC 1.60 beta 4 and later, BC-FJA 1.0.2 and later.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-1000180 bouncycastle: flaw in the low-level interface to RSA key pair generator
bugzilla·2018-06-07·CVSS 7.5
CVE-2018-1000180 [HIGH] CVE-2018-1000180 bouncycastle: flaw in the low-level interface to RSA key pair generator
CVE-2018-1000180 bouncycastle: flaw in the low-level interface to RSA key pair generator
Bouncy Castle BC 1.54 - 1.59, BC-FJA 1.0.0, BC-FJA 1.0.1 and earlier have a flaw in the Low-level interface to RSA key pair generator, specifically RSA Key Pairs generated in low-level API with added certainty may have less M-R tests than expected. This appears to be fixed in versions BC 1.60 beta 4 and later, BC-FJA 1.0.2 and later.
Upstream Issue:
https://www.bouncycastle.org/jira/browse/BJA-694
Upstream Commits:
https://github.com/bcgit/bc-java/commit/22467b6e8fe19717ecdf201c0cf91bacf04a55ad
https://github.com/bcgit/bc-java/commit/73780ac522b7795fc165630aba8d5f5729acc839
Discussion:
Created bouncycastle tracking bugs for this issue:
Affects: epel-all [bug 1588307]
Affects: fedora-all [bug
Bugzilla
CVE-2018-1000180 bouncycastle: flaw in the low-level interface to RSA key pair generator [fedora-all]
bugzilla·2018-06-07·CVSS 7.5
CVE-2018-1000180 [HIGH] CVE-2018-1000180 bouncycastle: flaw in the low-level interface to RSA key pair generator [fedora-all]
CVE-2018-1000180 bouncycastle: flaw in the low-level interface to RSA key pair generator [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects mul
Bugzilla
CVE-2018-1000180 bouncycastle: flaw in the low-level interface to RSA key pair generator [epel-all]
bugzilla·2018-06-07·CVSS 7.5
CVE-2018-1000180 [HIGH] CVE-2018-1000180 bouncycastle: flaw in the low-level interface to RSA key pair generator [epel-all]
CVE-2018-1000180 bouncycastle: flaw in the low-level interface to RSA key pair generator [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multipl
http://www.securityfocus.com/bid/106567https://access.redhat.com/errata/RHSA-2018:2423https://access.redhat.com/errata/RHSA-2018:2424https://access.redhat.com/errata/RHSA-2018:2425https://access.redhat.com/errata/RHSA-2018:2428https://access.redhat.com/errata/RHSA-2018:2643https://access.redhat.com/errata/RHSA-2018:2669https://access.redhat.com/errata/RHSA-2019:0877https://github.com/bcgit/bc-java/commit/22467b6e8fe19717ecdf201c0cf91bacf04a55adhttps://github.com/bcgit/bc-java/commit/73780ac522b7795fc165630aba8d5f5729acc839https://github.com/bcgit/bc-java/wiki/CVE-2018-1000180https://lists.apache.org/thread.html/708d94141126eac03011144a971a6411fcac16d9c248d1d535a39451%40%3Csolr-user.lucene.apache.org%3Ehttps://security.netapp.com/advisory/ntap-20190204-0003/https://www.bountysource.com/issues/58293083-rsa-key-generation-computation-of-iterations-for-mr-primality-testhttps://www.debian.org/security/2018/dsa-4233https://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpuapr2020.htmlhttps://www.oracle.com/security-alerts/cpuoct2020.htmlhttps://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.htmlhttps://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.htmlhttps://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.htmlhttp://www.securityfocus.com/bid/106567https://access.redhat.com/errata/RHSA-2018:2423https://access.redhat.com/errata/RHSA-2018:2424https://access.redhat.com/errata/RHSA-2018:2425https://access.redhat.com/errata/RHSA-2018:2428https://access.redhat.com/errata/RHSA-2018:2643https://access.redhat.com/errata/RHSA-2018:2669https://access.redhat.com/errata/RHSA-2019:0877https://github.com/bcgit/bc-java/commit/22467b6e8fe19717ecdf201c0cf91bacf04a55adhttps://github.com/bcgit/bc-java/commit/73780ac522b7795fc165630aba8d5f5729acc839https://github.com/bcgit/bc-java/wiki/CVE-2018-1000180https://lists.apache.org/thread.html/708d94141126eac03011144a971a6411fcac16d9c248d1d535a39451%40%3Csolr-user.lucene.apache.org%3Ehttps://security.netapp.com/advisory/ntap-20190204-0003/https://www.bountysource.com/issues/58293083-rsa-key-generation-computation-of-iterations-for-mr-primality-testhttps://www.debian.org/security/2018/dsa-4233https://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpuapr2020.htmlhttps://www.oracle.com/security-alerts/cpuoct2020.htmlhttps://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.htmlhttps://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.htmlhttps://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
2018-06-05
Published