← Back

CVE-2016-1000342

nvd nist
Published: Jun 4, 2018Modified: May 12, 2025

JSON object

Loading...
7.5
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

In the Bouncy Castle JCE Provider version 1.55 and earlier ECDSA does not fully validate ASN.1 encoding of signature on verification. It is possible to inject extra elements in the sequence making up the signature and still have it validate, which in some cases may allow the introduction of 'invisible' data into a signed structure.

Affected (2)

1 product
Bc Java
1 product
Debian Linux
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 1.55
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 8.0

References (14)

Timeline

No history available yet.