Oval Definition:oval:org.cisecurity:def:349
Revision Date:2016-02-26Version:2
Title:DSA-3417-1 -- bouncycastle -- security update
Description:Tibor Jager, Jörg Schwenk, and Juraj Somorovsky, from Horst Görtz Institute for IT Security, published a paper in ESORICS 2015 where they describe an invalid curve attack in Bouncy Castle Crypto, a Java library for cryptography. An attacker is able to recover private Elliptic Curve keys from different applications, for example, TLS servers.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2015-7940
DSA-3417-1
Platform(s):Debian 8
Debian GNU/kFreeBSD 7.0
Debian GNU/Linux 7.0
Product(s):bouncycastle
Definition Synopsis
  • Debian 7
  • Debian 7 is installed
  • AND GNU/Linux or GNU/kFreeBSD kernel
  • Debian GNU/Linux is installed
  • OR Debian GNU/kFreeBSD is installed
  • AND bouncycastle is earlier than 0:1.44+dfsg-3.1+deb7u1
  • OR Debian 8
  • Debian 8 is installed
  • AND bouncycastle is earlier than 0:1.49+dfsg-3+deb8u1
  • BACK