CVE-2018-1000180

Bouncy Castle BC 1.54 - 1.59, BC-FJA 1.0.0, BC-FJA 1.0.1 and earlier have a flaw in the Low-level interface to RSA key pair generator, specifically RSA Key Pairs generated in low-level API with added certainty may have less M-R tests than expected. This appears to be fixed in versions BC 1.60 beta 4 and later, BC-FJA 1.0.2 and later.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 47%
VendorProductVersion
bouncycastlebc-java
1.54 ≤
𝑥
≤ 1.59
bouncycastlefips_java_api
𝑥
≤ 1.0.1
debiandebian_linux
9.0
oracleapi_gateway
11.1.2.4.0
oraclebusiness_process_management_suite
11.1.1.9.0
oraclebusiness_process_management_suite
12.1.3.0.0
oraclebusiness_process_management_suite
12.2.1.3.0
oraclebusiness_transaction_management
12.1.0
oraclecommunications_application_session_controller
3.7.1
oraclecommunications_application_session_controller
3.8.0
oraclecommunications_converged_application_server
𝑥
< 7.0.0.1
oraclecommunications_webrtc_session_controller
𝑥
< 7.2
oracleenterprise_repository
12.1.3.0.0
oraclemanaged_file_transfer
12.1.3.0.0
oraclemanaged_file_transfer
12.2.1.3.0
oraclepeoplesoft_enterprise_peopletools
8.55
oraclepeoplesoft_enterprise_peopletools
8.56
oraclepeoplesoft_enterprise_peopletools
8.57
oracleretail_convenience_and_fuel_pos_software
2.8.1
oracleretail_xstore_point_of_service
7.0
oracleretail_xstore_point_of_service
7.1
oraclesoa_suite
12.1.3.0.0
oraclesoa_suite
12.2.1.3.0
oraclewebcenter_portal
11.1.1.9.0
oraclewebcenter_portal
12.2.1.3.0
oracleweblogic_server
12.1.3.0.0
netapponcommand_workflow_automation
-
redhatvirtualization
4.2
redhatjboss_enterprise_application_platform
7.1.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
bouncycastle
bullseye
1.68-2
fixed
jessie
not-affected
bookworm
1.72-2
fixed
sid
1.77-1
fixed
trixie
1.77-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
bouncycastle
noble
not-affected
mantic
not-affected
lunar
not-affected
kinetic
not-affected
jammy
not-affected
impish
not-affected
hirsute
not-affected
groovy
not-affected
focal
not-affected
eoan
not-affected
disco
not-affected
cosmic
not-affected
bionic
needed
artful
ignored
xenial
not-affected
trusty
dne
References