[FREEBSD:6A131FBF-EC76-11E7-AA65-001B216D295B] The Bouncy Castle Crypto APIs: CVE-2017-13098 ("ROBOT")
Severity
Medium
Affected Packages
2
CVEs
1
The Legion of the Bouncy Castle reports:
Release: 1.59
CVE-2017-13098 ("ROBOT"), a Bleichenbacher oracle in TLS
when RSA key exchange is negotiated. This potentially affected
BCJSSE servers and any other TLS servers configured to use JCE
for the underlying crypto - note the two TLS implementations
using the BC lightweight APIs are not affected by this.
Package | Affected Version |
---|---|
pkg:freebsd/bouncycastle15 | < 1.59 |
pkg:freebsd/bouncycastle | < 1.59 |
- ID
- FREEBSD:6A131FBF-EC76-11E7-AA65-001B216D295B
- Severity
- medium
- Severity from
- CVE-2017-13098
- URL
- http://vuxml.freebsd.org/freebsd/6a131fbf-ec76-11e7-aa65-001b216d295b.html
- Published
-
2017-12-12T00:00:00
(6 years ago) - Modified
-
2017-12-29T00:00:00
(6 years ago) - Rights
- FreeBSD VuXML Security Team
- Other Advisories
Source | # ID | Name | URL |
---|---|---|---|
FreeBSD VuXML | https://www.bouncycastle.org/releasenotes.html |
Type | Package URL | Namespace | Name / Product | Version | Distribution / Platform | Arch | Patch / Fix |
---|---|---|---|---|---|---|---|
Affected | pkg:freebsd/bouncycastle15 | bouncycastle15 | < 1.59 | ||||
Affected | pkg:freebsd/bouncycastle | bouncycastle | < 1.59 |
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |