CVE-2016-1000342
In the Bouncy Castle JCE Provider version 1.55 and earlier ECDSA does not fully validate ASN.1 encoding of signature on verification. It is possible to inject extra elements in the sequence making up the signature and still have it validate, which in some cases may allow the introduction of 'invisible' data into a signed structure. Upstream patch: https://github.com/bcgit/bc-java/commit/843c2e60f67d71faf81d236f448ebbe56c62c647#diff-25c3c78db788365f36839b3f2d3016b9
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2016-1000342?
CVE-2016-1000342 is a vulnerability in the Bouncy Castle JCE Provider that could provide weaker than expected security caused by improper validation.
What is the severity level of CVE-2016-1000342?
CVE-2016-1000342 has a severity level of 7.5 (high).
What software is affected by CVE-2016-1000342?
Bouncy Castle JCE Provider version 1.55 and earlier is affected by CVE-2016-1000342.
How can I fix CVE-2016-1000342?
To fix CVE-2016-1000342, you should update your Bouncy Castle JCE Provider to version 1.56-1 or later.
Where can I find more information about CVE-2016-1000342?
You can find more information about CVE-2016-1000342 on the MITRE CVE website, the Ubuntu security notices, and the NVD.