Vulnerability Name:

CVE-2018-5382

Assigned:2018-01-12
Published:2018-03-19
Updated:2018-04-17
Summary:Bouncy Castle BKS version 1 keystore (BKS-V1) files use an HMAC that is only 16 bits long, which can allow an attacker to compromise the integrity of a BKS-V1 keystore. All BKS-V1 keystores are vulnerable. Bouncy Castle release 1.47 introduces BKS version 2, which uses a 160-bit MAC.
CVSS v3 Severity:4.4 Medium (CCN CVSS v3 Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N)
3.9 Low (CCN Temporal CVSS v3 Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:3.2 Low (CCN CVSS v2 Vector: AV:L/AC:L/Au:S/C:P/I:P/A:N)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): None
References:Source: BID
Type: UNKNOWN
103453

Source: XF
Type: UNKNOWN
bouncy-castle-cve20185382-info-disc(140465)

Source: MISC
Type: UNKNOWN
https://www.bouncycastle.org/releasenotes.html

Source: CERT-VN
Type: UNKNOWN
VU#306792

Oval Definitions
Definition IDClassTitleLast Modified
oval:com.ubuntu.artful:def:20185382000
V
CVE-2018-5382 on Ubuntu 17.10 (artful) - medium.
2018-04-16
oval:com.ubuntu.xenial:def:20185382000
V
CVE-2018-5382 on Ubuntu 16.04 LTS (xenial) - medium.
2018-04-16
oval:com.ubuntu.trusty:def:20185382000
V
CVE-2018-5382 on Ubuntu 14.04 LTS (trusty) - medium.
2018-04-16
BACK