REDHAT-BUG-2458634: High severity Bouncy Castle BC-JAVA bcpkix vulnerability
: Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcpkix on all (pkix modules).
PKIX draft CompositeVerifier accepts empty signature sequence as valid.
This issue affects BC-JAVA: from 1.49 before 1.84.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2458634?
The severity of REDHAT-BUG-2458634 is classified as high with a score of 7.
What does REDHAT-BUG-2458634 describe?
REDHAT-BUG-2458634 describes a vulnerability involving a broken or risky cryptographic algorithm in Bouncy Castle BC-JAVA, where the PKIX draft CompositeVerifier incorrectly accepts an empty signature sequence as valid.
Which versions of BC-JAVA are affected by REDHAT-BUG-2458634?
REDHAT-BUG-2458634 affects Bouncy Castle BC-JAVA versions from 1.49 up to but not including 1.84.
How do I fix REDHAT-BUG-2458634?
To remediate REDHAT-BUG-2458634, upgrade to a patched version of the Bouncy Castle BC-JAVA library that is 1.84 or later.
What impact does REDHAT-BUG-2458634 have on security?
The impact of REDHAT-BUG-2458634 is significant as it can allow an attacker to manipulate cryptographic validation processes, potentially leading to unauthorized access or data breaches.