[MAVEN:GHSA-4VHJ-98R6-424H] In Bouncy Castle JCE Provider it is possible to inject extra elements in the sequence making up the signature and still have it validate

Severity High
Affected Packages 2
Fixed Packages 2
CVEs 1

In Bouncy Castle JCE Provider version 1.55 and earlier the DSA does not fully validate ASN.1 encoding of signature on verification. It is possible to inject extra elements in the sequence making up the signature and still have it validate, which in some cases may allow the introduction of 'invisible' data into a signed structure.

ID
MAVEN:GHSA-4VHJ-98R6-424H
Severity
high
URL
https://github.com/advisories/GHSA-4vhj-98r6-424h
Published
2018-10-17T16:23:26
(6 years ago)
Modified
2023-11-10T05:00:48
(10 months ago)
Rights
Maven Security Team
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.bouncycastle/bcprov-jdk15 org.bouncycastle bcprov-jdk15 < 1.5.6
Fixed pkg:maven/org.bouncycastle/bcprov-jdk15 org.bouncycastle bcprov-jdk15 = 1.5.6
Affected pkg:maven/org.bouncycastle/bcprov-jdk14 org.bouncycastle bcprov-jdk14 < 1.56
Fixed pkg:maven/org.bouncycastle/bcprov-jdk14 org.bouncycastle bcprov-jdk14 = 1.56
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...