ZeroHour

CVE-2016-1000342

CVSS 3.0
7.5 high
EPSS
2%p77
Published
()
Modified
Description

In the Bouncy Castle JCE Provider version 1.55 and earlier ECDSA does not fully validate ASN.1 encoding of signature on verification. It is possible to inject extra elements in the sequence making up the signature and still have it validate, which in some cases may allow the introduction of 'invisible' data into a signed structure.

Vendors
bouncycastledebian
Products
bc-java, debian linux
Weakness
CWE-347
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.