Bouncycastle

Fips Java Api

5 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.06%
  • Veröffentlicht 23.11.2023 16:15:07
  • Zuletzt bearbeitet 18.08.2025 17:15:27

Bouncy Castle for Java before 1.73 contains a potential Denial of Service (DoS) issue within the Bouncy Castle org.bouncycastle.openssl.PEMParser class. This class parses OpenSSL PEM encoded streams containing X.509 certificates, PKCS8 encoded keys, ...

Exploit
  • EPSS 0.1%
  • Veröffentlicht 21.11.2022 10:15:31
  • Zuletzt bearbeitet 21.11.2024 07:28:50

An issue was discovered in the FIPS Java API of Bouncy Castle BC-FJA before 1.0.2.4. Changes to the JVM garbage collector in Java 13 and later trigger an issue in the BC-FJA FIPS modules where it is possible for temporary keys used by the module to b...

  • EPSS 0.4%
  • Veröffentlicht 20.05.2021 12:15:08
  • Zuletzt bearbeitet 17.07.2025 17:04:58

Bouncy Castle BC Java before 1.66, BC C# .NET before 1.8.7, BC-FJA before 1.0.1.2, 1.0.2.1, and BC-FNA before 1.0.1.1 have a timing issue within the EC math library that can expose information about the private key when an attacker is able to observe...

  • EPSS 2.44%
  • Veröffentlicht 02.11.2020 22:15:13
  • Zuletzt bearbeitet 17.07.2025 17:04:58

In Legion of the Bouncy Castle BC before 1.61 and BC-FJA before 1.0.1.2, attackers can obtain sensitive information about a private exponent because of Observable Differences in Behavior to Error Inputs. This occurs in org.bouncycastle.crypto.encodin...

  • EPSS 0.24%
  • Veröffentlicht 05.06.2018 13:29:00
  • Zuletzt bearbeitet 12.05.2025 17:37:16

Bouncy Castle BC 1.54 - 1.59, BC-FJA 1.0.0, BC-FJA 1.0.1 and earlier have a flaw in the Low-level interface to RSA key pair generator, specifically RSA Key Pairs generated in low-level API with added certainty may have less M-R tests than expected. T...