CVE-2020-15522: Race Condition
A flaw was found in bouncycastle. A timing issue within the EC math library can expose information about the private key when an attacker is able to observe timing information for the generation of multiple deterministic ECDSA signatures.
Other sources
Bouncy Castle BC Java before 1.66, BC C# .NET before 1.8.7, BC-FJA before 1.0.1.2, 1.0.2.1, and BC-FNA before 1.0.1.1 have a timing issue within the EC math library that can expose information about the private key when an attacker is able to observe timing information for the generation of multiple deterministic ECDSA signatures.
Bouncy Castle BC Java before 1.66, BC C# .NET before 1.8.7, BC-FJA before 1.0.2.1, BC before 1.66, BC-FNA before 1.0.1.1 have a timing issue within the EC math library that can expose information about the private key when an attacker is able to observe timing information for the generation of multiple deterministic ECDSA signatures.
— GitHub
Bouncy Castle BC Java, BC C# .NET, BC-FJA, BC-FNA could allow a remote attacker to obtain sensitive information, caused by a timing issue within the EC math library. By utilize cryptographic attack techniques, an attacker could exploit this vulnerability to obtain the private key information, and use this information to launch further attacks against the affected system.
— IBM
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the vulnerability ID of this flaw in bouncycastle?
The vulnerability ID is CVE-2020-15522.
What is the severity rating of CVE-2020-15522?
The severity rating of CVE-2020-15522 is medium with a CVSS score of 5.9.
Which software versions are affected by CVE-2020-15522?
Bouncy Castle BC Java before 1.66, BC C# .NET before 1.8.7, BC-FJA before 1.0.2.1, BC before 1.66, BC-FNA before 1.0.1.1.
How can this vulnerability be fixed?
To fix CVE-2020-15522, update Bouncy Castle BC Java to version 1.66 or higher, BC C# .NET to version 1.8.7 or higher, BC-FJA to version 1.0.2.1 or higher, and BC-FNA to version 1.0.1.1 or higher.
Where can I find more information about CVE-2020-15522?
More information about CVE-2020-15522 can be found at the following references: [NIST NVD](https://nvd.nist.gov/vuln/detail/CVE-2020-15522), [GitHub - bc-csharp](https://github.com/bcgit/bc-csharp/wiki/CVE-2020-15522), [GitHub - bc-java](https://github.com/bcgit/bc-java/wiki/CVE-2020-15522).