CVE-2016-1000343: High severity bouncycastle Legion-of-the-bouncy-castle-java-crytography-api vulnerability
Bouncy Castle JCE Provider could provide weaker than expected security, caused by a flaw in the DSA key pair generator. A remote attacker could exploit this vulnerability to launch further attacks.
Other sources
In the Bouncy Castle JCE Provider version 1.55 and earlier the DSA key pair generator generates a weak private key if used with default values. If the JCA key pair generator is not explicitly initialised with DSA parameters, 1.55 and earlier generates a private value assuming a 1024 bit key size. In earlier releases this can be dealt with by explicitly passing parameters to the key pair generator.
Upstream patch:
https://github.com/bcgit/bc-java/commit/50a53068c094d6cff37659da33c9b4505becd389#diff-5578e61500abb2b87b300d3114bdfd7d
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2016-1000343?
CVE-2016-1000343 is a vulnerability in the Bouncy Castle JCE Provider that could provide weaker than expected security due to a flaw in the DSA key pair generator.
How does CVE-2016-1000343 affect Bouncy Castle JCE Provider?
CVE-2016-1000343 affects Bouncy Castle JCE Provider version 1.55 and earlier.
What is the severity of CVE-2016-1000343?
CVE-2016-1000343 has a severity rating of high (7.5).
Is there a fix available for CVE-2016-1000343 in Bouncy Castle JCE Provider?
Yes, the fix for CVE-2016-1000343 is available in version 1.56-1 of Bouncy Castle JCE Provider.
Where can I find more information about CVE-2016-1000343?
More information about CVE-2016-1000343 can be found at the following references: [CVE-2016-1000343](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1000343), [Ubuntu Security Notice USN-3727-1](https://ubuntu.com/security/notices/USN-3727-1), [NIST CVE-2016-1000343](https://nvd.nist.gov/vuln/detail/CVE-2016-1000343).