CVE-2016-1000345: Medium severity bouncycastle Legion-of-the-bouncy-castle-java-crytography-api vulnerability
Bouncy Castle JCE Provider could provide weaker than expected security, caused by an environment where timings can be easily observed. A remote attacker could exploit this vulnerability to conduct a padding oracle attack.
Other sources
In the Bouncy Castle JCE Provider version 1.55 and earlier the DHIES/ECIES CBC mode vulnerable to padding oracle attack. For BC 1.55 and older, in an environment where timings can be easily observed, it is possible with enough observations to identify when the decryption is failing due to padding.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2016-1000345.
What is the severity level of CVE-2016-1000345?
The severity level of CVE-2016-1000345 is medium, with a severity value of 5.9.
What software is affected by CVE-2016-1000345?
The Bouncy Castle JCE Provider version 1.55 and earlier is affected by CVE-2016-1000345.
How can I fix the vulnerability CVE-2016-1000345?
To fix the vulnerability CVE-2016-1000345, update to Bouncy Castle JCE Provider version 1.56 or later.
Is there any additional information available about CVE-2016-1000345?
Yes, you can find additional information about CVE-2016-1000345 at the following references: [Reference 1](https://github.com/bcgit/bc-java/commit/21dcb3d9744c83dcf2ff8fcee06dbca7bfa4ef35#diff-4439ce586bf9a13bfec05c0d113b8098), [Reference 2](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1588325), [Reference 3](https://access.redhat.com/security/updates/classification/).