[FREEBSD:6A131FBF-EC76-11E7-AA65-001B216D295B] The Bouncy Castle Crypto APIs: CVE-2017-13098 ("ROBOT")

Severity Medium
Affected Packages 2
CVEs 1

The Legion of the Bouncy Castle reports:

  Release: 1.59
  CVE-2017-13098 ("ROBOT"), a Bleichenbacher oracle in TLS
     when RSA key exchange is negotiated. This potentially affected
     BCJSSE servers and any other TLS servers configured to use JCE
     for the underlying crypto - note the two TLS implementations
     using the BC lightweight APIs are not affected by this.
Package Affected Version
pkg:freebsd/bouncycastle15 < 1.59
pkg:freebsd/bouncycastle < 1.59
ID
FREEBSD:6A131FBF-EC76-11E7-AA65-001B216D295B
Severity
medium
Severity from
CVE-2017-13098
URL
http://vuxml.freebsd.org/freebsd/6a131fbf-ec76-11e7-aa65-001b216d295b.html
Published
2017-12-12T00:00:00
(6 years ago)
Modified
2017-12-29T00:00:00
(6 years ago)
Rights
FreeBSD VuXML Security Team
Other Advisories
Source # ID Name URL
FreeBSD VuXML https://www.bouncycastle.org/releasenotes.html
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:freebsd/bouncycastle15 bouncycastle15 < 1.59
Affected pkg:freebsd/bouncycastle bouncycastle < 1.59
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...