Oval Definition:oval:com.ubuntu.xenial:def:201610003380000000
Revision Date:2018-06-01Version:1
Title:CVE-2016-1000338 on Ubuntu 16.04 LTS (xenial) - medium.
Description:In Bouncy Castle JCE Provider version 1.55 and earlier the DSA does not fully validate ASN.1 encoding of signature on verification. It is possible to inject extra elements in the sequence making up the signature and still have it validate, which in some cases may allow the introduction of 'invisible' data into a signed structure.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2016-1000338
Platform(s):Ubuntu 16.04 LTS
Product(s):
Definition Synopsis
  • Ubuntu 16.04 LTS (xenial) is installed.
  • AND bouncycastle package in xenial is affected and needs fixing.
  • BACK