Oval Definition:oval:com.ubuntu.bionic:def:201610003460000000
Revision Date:2018-06-04Version:1
Title:CVE-2016-1000346 on Ubuntu 18.04 LTS (bionic) - medium.
Description:In the Bouncy Castle JCE Provider version 1.55 and earlier the other party DH public key is not fully validated. This can cause issues as invalid keys can be used to reveal details about the other party's private key where static Diffie-Hellman is in use. As of release 1.56 the key parameters are checked on agreement calculation.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2016-1000346
Platform(s):Ubuntu 18.04 LTS
Product(s):
Definition Synopsis
  • Ubuntu 18.04 LTS (bionic) is installed.
  • AND bouncycastle package in bionic, is related to the CVE in some way and has been fixed (note: '1.59-1').
  • BACK