CVE-2018-1000613: Critical severity bouncycastle Legion-of-the-bouncy-castle-java-crytography-api vulnerability
Legion of the Bouncy Castle Java Cryptography APIs could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe reflection flaw in XMSS/XMSS^MT private key deserialization. By using specially-crafted private key, an attacker could exploit this vulnerability to execute arbitrary code on the system.
Other sources
Legion of the Bouncy Castle Java Cryptography APIs starting in version 1.57 and prior to version 1.60 contains a CWE-470: Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in XMSS/XMSS^MT private key deserialization that can result in Deserializing an XMSS/XMSS^MT private key can result in the execution of unexpected code. This attack appear to be exploitable via A handcrafted private key can include references to unexpected classes which will be picked up from the class path for the executing application.
This vulnerability appears to have been fixed in 1.60 and later.
— GitHub
Legion of the Bouncy Castle Legion of the Bouncy Castle Java Cryptography APIs 1.58 up to but not including 1.60 contains a CWE-470: Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in XMSS/XMSS^MT private key deserialization that can result in Deserializing an XMSS/XMSS^MT private key can result in the execution of unexpected code. This attack appear to be exploitable via A handcrafted private key can include references to unexpected classes which will be picked up from the class path for the executing application. This vulnerability appears to have been fixed in 1.60 and later.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2018-1000613?
CVE-2018-1000613 is a vulnerability in Legion of the Bouncy Castle Java Cryptography APIs that allows a remote attacker to execute arbitrary code.
What is the severity of CVE-2018-1000613?
The severity of CVE-2018-1000613 is critical with a CVSS score of 9.8.
How does CVE-2018-1000613 affect the Legion of the Bouncy Castle Java Cryptography APIs?
CVE-2018-1000613 affects versions 1.57 to 1.60 of the Legion of the Bouncy Castle Java Cryptography APIs.
How can I fix CVE-2018-1000613?
To fix CVE-2018-1000613, upgrade to version 1.60 of the Legion of the Bouncy Castle Java Cryptography APIs.
How can I learn more about CVE-2018-1000613?
You can learn more about CVE-2018-1000613 at the following references: [link1](https://nvd.nist.gov/vuln/detail/CVE-2018-1000613), [link2](https://github.com/bcgit/bc-java/commit/4092ede58da51af9a21e4825fbad0d9a3ef5a223#diff-2c06e2edef41db889ee14899e12bd574), [link3](https://github.com/bcgit/bc-java/commit/cd98322b171b15b3f88c5ec871175147893c31e6#diff-148a6c098af0199192d6aede960f45dc).