CVE-2017-13098
MEDIUM5.9EPSS 68.1%bouncycastle - security update
發布日:2022/5/13修改日:2026/4/28
描述
BouncyCastle TLS prior to version 1.0.3, when configured to use the JCE (Java Cryptography Extension) for cryptographic functions, provides a weak Bleichenbacher oracle when any TLS cipher suite using RSA key exchange is negotiated. An attacker can recover the private key from a vulnerable application. This vulnerability is referred to as "ROBOT."
受影響套件(3)
- Debian/bouncycastlefrom 0, < 1.58-1
- Debian/bouncycastlefrom 0, < 1.56-1+deb9u1
- Maven/org.bouncycastle:bcprov-jdk15onfrom 0, < 1.0.3
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.9 | CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N |
參考連結(10)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2017-13098
- ADVISORYhttps://security-tracker.debian.org/tracker/CVE-2017-13098
- PATCHhttps://github.com/bcgit/bc-java
- WEBhttp://lists.opensuse.org/opensuse-security-announce/2020-05/msg00011.html
- WEBhttps://github.com/bcgit/bc-java/commit/a00b684465b38d722ca9a3543b8af8568e6bad5c
- WEBhttps://robotattack.org
- WEBhttps://security.netapp.com/advisory/ntap-20171222-0001
- WEBhttps://www.debian.org/security/2017/dsa-4072
- WEBhttps://www.oracle.com/security-alerts/cpuoct2020.html
- WEBhttp://www.kb.cert.org/vuls/id/144389