CVE-2020-26939
published 2020-11-02CVE-2020-26939: In Legion of the Bouncy Castle BC before 1.61 and BC-FJA before 1.0.1.2, attackers can obtain sensitive information about a private exponent because of…
PriorityP424medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
0.91%
56.1th percentile
In Legion of the Bouncy Castle BC before 1.61 and BC-FJA before 1.0.1.2, attackers can obtain sensitive information about a private exponent because of Observable Differences in Behavior to Error Inputs. This occurs in org.bouncycastle.crypto.encodings.OAEPEncoding. Sending invalid ciphertext that decrypts to a short payload in the OAEP Decoder could result in the throwing of an early exception, potentially leaking some information about the private exponent of the RSA private key performing the encryption.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| bouncycastle | fips_java_api | < 1.0.1.2 | 1.0.1.2 |
| bouncycastle | legion-of-the-bouncy-castle | < 1.61 | 1.61 |
| debian | bouncycastle | < bouncycastle 1.61-1 (bookworm) | bouncycastle 1.61-1 (bookworm) |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv5.3MEDIUM
vendor_debian5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Observable Differences in Behavior to Error Inputs in Bouncy Castle
osv·2021-04-22
CVE-2020-26939 [MEDIUM] Observable Differences in Behavior to Error Inputs in Bouncy Castle
Observable Differences in Behavior to Error Inputs in Bouncy Castle
In Legion of the Bouncy Castle BC before 1.55 and BC-FJA before 1.0.2, attackers can obtain sensitive information about a private exponent because of Observable Differences in Behavior to Error Inputs. This occurs in org.bouncycastle.crypto.encodings.OAEPEncoding. Sending invalid ciphertext that decrypts to a short payload in the OAEP Decoder could result in the throwing of an early exception, potentially leaking some information about the private exponent of the RSA private key performing the encryption.
GHSA
Observable Differences in Behavior to Error Inputs in Bouncy Castle
ghsa·2021-04-22
CVE-2020-26939 [MEDIUM] CWE-203 Observable Differences in Behavior to Error Inputs in Bouncy Castle
Observable Differences in Behavior to Error Inputs in Bouncy Castle
In Legion of the Bouncy Castle BC before 1.55 and BC-FJA before 1.0.2, attackers can obtain sensitive information about a private exponent because of Observable Differences in Behavior to Error Inputs. This occurs in org.bouncycastle.crypto.encodings.OAEPEncoding. Sending invalid ciphertext that decrypts to a short payload in the OAEP Decoder could result in the throwing of an early exception, potentially leaking some information about the private exponent of the RSA private key performing the encryption.
OSV
CVE-2020-26939: In Legion of the Bouncy Castle BC before 1
osv·2020-11-02·CVSS 5.3
CVE-2020-26939 [MEDIUM] CVE-2020-26939: In Legion of the Bouncy Castle BC before 1
In Legion of the Bouncy Castle BC before 1.61 and BC-FJA before 1.0.1.2, attackers can obtain sensitive information about a private exponent because of Observable Differences in Behavior to Error Inputs. This occurs in org.bouncycastle.crypto.encodings.OAEPEncoding. Sending invalid ciphertext that decrypts to a short payload in the OAEP Decoder could result in the throwing of an early exception, potentially leaking some information about the private exponent of the RSA private key performing the encryption.
Debian
CVE-2020-26939: bouncycastle - In Legion of the Bouncy Castle BC before 1.61 and BC-FJA before 1.0.1.2, attacke...
vendor_debian·2020·CVSS 5.3
CVE-2020-26939 [MEDIUM] CVE-2020-26939: bouncycastle - In Legion of the Bouncy Castle BC before 1.61 and BC-FJA before 1.0.1.2, attacke...
In Legion of the Bouncy Castle BC before 1.61 and BC-FJA before 1.0.1.2, attackers can obtain sensitive information about a private exponent because of Observable Differences in Behavior to Error Inputs. This occurs in org.bouncycastle.crypto.encodings.OAEPEncoding. Sending invalid ciphertext that decrypts to a short payload in the OAEP Decoder could result in the throwing of an early exception, potentially leaking some information about the private exponent of the RSA private key performing the encryption.
Scope: local
bookworm: resolved (fixed in 1.61-1)
bullseye: resolved (fixed in 1.61-1)
forky: resolved (fixed in 1.61-1)
sid: resolved (fixed in 1.61-1)
trixie: resolved (fixed in 1.61-1)
No detection rules found.
No public exploits indexed.
https://github.com/bcgit/bc-java/wiki/CVE-2020-26939https://lists.apache.org/thread.html/r8c36ba34e80e05eecb1f80071cc834d705616f315b634ec0c7d8f42e%40%3Cissues.solr.apache.org%3Ehttps://github.com/bcgit/bc-java/wiki/CVE-2020-26939https://lists.apache.org/thread.html/r8c36ba34e80e05eecb1f80071cc834d705616f315b634ec0c7d8f42e%40%3Cissues.solr.apache.org%3E
2020-11-02
Published