ZeroHour

CVE-2018-1000180

CVSS 3.0
7.5 high
EPSS
4%p89
Published
()
Modified
Description

Bouncy Castle BC 1.54 - 1.59, BC-FJA 1.0.0, BC-FJA 1.0.1 and earlier have a flaw in the Low-level interface to RSA key pair generator, specifically RSA Key Pairs generated in low-level API with added certainty may have less M-R tests than expected. This appears to be fixed in versions BC 1.60 beta 4 and later, BC-FJA 1.0.2 and later.

Vendors
bouncycastledebianoraclenetappredhat
Products
bc-java, fips java api, debian linux, api gateway, business process management suite, business transaction management, communications application session controller, communications converged application server, communications webrtc session controller, enterprise repository, managed file transfer, peoplesoft enterprise peopletools
Weakness
CWE-327
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.