Description
The Bouncy Castle Java library before 1.51 does not validate a point is withing the elliptic curve, which makes it easier for remote attackers to obtain private keys via a series of crafted elliptic curve Diffie Hellman (ECDH) key exchanges, aka an "invalid curve attack."
References (21)
Core 21
Core References
Vendor Advisory vendor-advisory
x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2016-2035.html
Vendor Advisory x_refsource_confirm
http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html
Vendor Advisory x_refsource_confirm
https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/79091
Third Party Advisory vendor-advisory
x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00012.html
Mailing List, Third Party Advisory vendor-advisory
x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2016-January/174915.html
Third Party Advisory x_refsource_confirm
http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html
Vendor Advisory vendor-advisory
x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2016-2036.html
Vendor Advisory x_refsource_confirm
http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html
Vendor Advisory vendor-advisory
x_refsource_ubuntu
https://usn.ubuntu.com/3727-1/
Third Party Advisory, VDB Entry mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2015/10/22/9
Vendor Advisory x_refsource_confirm
http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id/1037036
Third Party Advisory, VDB Entry mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2015/10/22/7
Third Party Advisory vendor-advisory
x_refsource_debian
http://www.debian.org/security/2015/dsa-3417
Vendor Advisory x_refsource_confirm
http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html
Technical Description x_refsource_misc
http://web-in-security.blogspot.ca/2015/09/practical-invalid-curve-attacks.html
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id/1037046
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id/1037053
Vendor Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpuapr2020.html
Vendor Advisory x_refsource_confirm
http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html
Scores
EPSS
0.0097
EPSS Percentile
76.9%
Details
CWE
CWE-200
CWE-310
Status
published
Products (15)
bouncycastle/bouncy_castle_crypto_package
< 1.50
opensuse/leap
42.1
opensuse/opensuse
13.1
opensuse/opensuse
13.2
oracle/application_testing_suite
12.5.0.1
oracle/application_testing_suite
12.5.0.2
oracle/application_testing_suite
12.5.0.3
oracle/enterprise_manager_ops_center
12.1.4
oracle/enterprise_manager_ops_center
12.2.2
oracle/peoplesoft_enterprise_peopletools
8.54
... and 5 more
Published
Nov 09, 2015
Tracked Since
Feb 18, 2026