REDHAT-BUG-2458640: High severity Bouncy Castle BC-JAVA bcprov vulnerability
Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcprov on all (core modules). This vulnerability is associated with program files G3413CTRBlockCipher.
GOSTCTR implementation unable to process more than 255 blocks correctly.
This issue affects BC-JAVA: from 1.59 before 1.84.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2458640?
The severity of REDHAT-BUG-2458640 is classified as high with a score of 7.
How do I fix REDHAT-BUG-2458640?
To fix REDHAT-BUG-2458640, upgrade to a patched version of Bouncy Castle BC-JAVA bcprov that addresses the cryptographic algorithm issue.
What does REDHAT-BUG-2458640 affect?
REDHAT-BUG-2458640 affects all core modules of the Bouncy Castle BC-JAVA bcprov library.
What is the main issue with GOSTCTR implementation in REDHAT-BUG-2458640?
The main issue with the GOSTCTR implementation in REDHAT-BUG-2458640 is its inability to correctly process more than 255 blocks.
Who is responsible for Bouncy Castle BC-JAVA bcprov?
Bouncy Castle BC-JAVA bcprov is maintained by the Legion of the Bouncy Castle Inc.