CVE-2016-1000346

CVE-2016-1000346

In the Bouncy Castle JCE Provider version 1.55 and earlier the other party DH public key is not fully validated. This can cause issues as invalid keys can be used to reveal details about the other party’s private key where static Diffie-Hellman is in use. As of release 1.56 the key parameters are checked on agreement calculation.

Source: CVE-2016-1000346

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다