CVE-2018-1000180
bouncycastle: flaw in the low-level interface to RSA key pair generator
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Bouncy Castle BC 1.54 - 1.59, BC-FJA 1.0.0, BC-FJA 1.0.1 and earlier have a flaw in the Low-level interface to RSA key pair generator, specifically RSA Key Pairs generated in low-level API with added certainty may have less M-R tests than expected. This appears to be fixed in versions BC 1.60 beta 4 and later, BC-FJA 1.0.2 and later.
Bouncy Castle BC 1.54 - 1.59, BC-FJA 1.0.0, BC-FJA 1.0.1 y anteriores tiene un vulnerabilidad en la interfaz de bajo nivel del generador de claves RSA; específicamente, los pares de claves RSA generados en la API de bajo nivel con un valor certainty añadido pueden tener menos tests M-R de lo esperado. Parece que se ha resuelto en versiones BC 1.60 beta 4 y posteriores y BC-FJA 1.0.2 y posteriores.
A vulnerability was found in BouncyCastle. The number of iterations of the Miller-Rabin primality test was incorrectly calculated (according to FIPS 186-4 C.3). Under some circumstances, this could lead to the generation of weak RSA key pairs.
Red Hat OpenShift Application Runtimes provides an application platform that reduces the complexity of developing and operating applications for OpenShift as a containerized platform. This release of RHOAR Thorntail 2.4.0 serves as a replacement for RHOAR Thorntail 2.2.0, and includes security and bug fixes and enhancements. For further information, refer to the release notes linked to in the References section. Issues addressed include code execution, denial of service, deserialization, and traversal vulnerabilities.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-04-30 CVE Reserved
- 2018-06-05 CVE Published
- 2024-08-05 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-325: Missing Cryptographic Step
- CWE-327: Use of a Broken or Risky Cryptographic Algorithm
CAPEC
References (23)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/106567 | Third Party Advisory | |
https://github.com/bcgit/bc-java/wiki/CVE-2018-1000180 | X_refsource_misc | |
https://lists.apache.org/thread.html/708d94141126eac03011144a971a6411fcac16d9c248d1d535a39451%40%3Csolr-user.lucene.apache.org%3E | Mailing List | |
https://www.bountysource.com/issues/58293083-rsa-key-generation-computation-of-iterations-for-mr-primality-test | Third Party Advisory | |
https://www.oracle.com/security-alerts/cpuApr2021.html | X_refsource_misc |
|
https://www.oracle.com/security-alerts/cpuapr2020.html | X_refsource_misc |
|
https://www.oracle.com/security-alerts/cpuoct2020.html | X_refsource_misc |
|
https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html | X_refsource_misc |
|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://access.redhat.com/errata/RHSA-2018:2423 | 2023-11-07 | |
https://access.redhat.com/errata/RHSA-2018:2424 | 2023-11-07 | |
https://access.redhat.com/errata/RHSA-2018:2425 | 2023-11-07 | |
https://access.redhat.com/errata/RHSA-2018:2428 | 2023-11-07 | |
https://access.redhat.com/errata/RHSA-2018:2643 | 2023-11-07 | |
https://access.redhat.com/errata/RHSA-2018:2669 | 2023-11-07 | |
https://access.redhat.com/errata/RHSA-2019:0877 | 2023-11-07 | |
https://www.debian.org/security/2018/dsa-4233 | 2023-11-07 | |
https://access.redhat.com/security/cve/CVE-2018-1000180 | 2019-04-24 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1588306 | 2019-04-24 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Redhat Search vendor "Redhat" | Jboss Enterprise Application Platform Search vendor "Redhat" for product "Jboss Enterprise Application Platform" | 7.1.0 Search vendor "Redhat" for product "Jboss Enterprise Application Platform" and version "7.1.0" | - |
Affected
| in | Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 6.0 Search vendor "Redhat" for product "Enterprise Linux" and version "6.0" | - |
Safe
|
Redhat Search vendor "Redhat" | Jboss Enterprise Application Platform Search vendor "Redhat" for product "Jboss Enterprise Application Platform" | 7.1.0 Search vendor "Redhat" for product "Jboss Enterprise Application Platform" and version "7.1.0" | - |
Affected
| in | Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 7.0 Search vendor "Redhat" for product "Enterprise Linux" and version "7.0" | - |
Safe
|
Bouncycastle Search vendor "Bouncycastle" | Fips Java Api Search vendor "Bouncycastle" for product "Fips Java Api" | <= 1.0.1 Search vendor "Bouncycastle" for product "Fips Java Api" and version " <= 1.0.1" | - |
Affected
| ||||||
Bouncycastle Search vendor "Bouncycastle" | Legion-of-the-bouncy-castle-java-crytography-api Search vendor "Bouncycastle" for product "Legion-of-the-bouncy-castle-java-crytography-api" | >= 1.54 <= 1.59 Search vendor "Bouncycastle" for product "Legion-of-the-bouncy-castle-java-crytography-api" and version " >= 1.54 <= 1.59" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 9.0 Search vendor "Debian" for product "Debian Linux" and version "9.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Api Gateway Search vendor "Oracle" for product "Api Gateway" | 11.1.2.4.0 Search vendor "Oracle" for product "Api Gateway" and version "11.1.2.4.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Business Process Management Suite Search vendor "Oracle" for product "Business Process Management Suite" | 11.1.1.9.0 Search vendor "Oracle" for product "Business Process Management Suite" and version "11.1.1.9.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Business Process Management Suite Search vendor "Oracle" for product "Business Process Management Suite" | 12.1.3.0.0 Search vendor "Oracle" for product "Business Process Management Suite" and version "12.1.3.0.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Business Process Management Suite Search vendor "Oracle" for product "Business Process Management Suite" | 12.2.1.3.0 Search vendor "Oracle" for product "Business Process Management Suite" and version "12.2.1.3.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Business Transaction Management Search vendor "Oracle" for product "Business Transaction Management" | 12.1.0 Search vendor "Oracle" for product "Business Transaction Management" and version "12.1.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Application Session Controller Search vendor "Oracle" for product "Communications Application Session Controller" | 3.7.1 Search vendor "Oracle" for product "Communications Application Session Controller" and version "3.7.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Application Session Controller Search vendor "Oracle" for product "Communications Application Session Controller" | 3.8.0 Search vendor "Oracle" for product "Communications Application Session Controller" and version "3.8.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Converged Application Server Search vendor "Oracle" for product "Communications Converged Application Server" | < 7.0.0.1 Search vendor "Oracle" for product "Communications Converged Application Server" and version " < 7.0.0.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Webrtc Session Controller Search vendor "Oracle" for product "Communications Webrtc Session Controller" | < 7.2 Search vendor "Oracle" for product "Communications Webrtc Session Controller" and version " < 7.2" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Enterprise Repository Search vendor "Oracle" for product "Enterprise Repository" | 12.1.3.0.0 Search vendor "Oracle" for product "Enterprise Repository" and version "12.1.3.0.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Managed File Transfer Search vendor "Oracle" for product "Managed File Transfer" | 12.1.3.0.0 Search vendor "Oracle" for product "Managed File Transfer" and version "12.1.3.0.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Managed File Transfer Search vendor "Oracle" for product "Managed File Transfer" | 12.2.1.3.0 Search vendor "Oracle" for product "Managed File Transfer" and version "12.2.1.3.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Peoplesoft Enterprise Peopletools Search vendor "Oracle" for product "Peoplesoft Enterprise Peopletools" | 8.55 Search vendor "Oracle" for product "Peoplesoft Enterprise Peopletools" and version "8.55" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Peoplesoft Enterprise Peopletools Search vendor "Oracle" for product "Peoplesoft Enterprise Peopletools" | 8.56 Search vendor "Oracle" for product "Peoplesoft Enterprise Peopletools" and version "8.56" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Peoplesoft Enterprise Peopletools Search vendor "Oracle" for product "Peoplesoft Enterprise Peopletools" | 8.57 Search vendor "Oracle" for product "Peoplesoft Enterprise Peopletools" and version "8.57" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Convenience And Fuel Pos Software Search vendor "Oracle" for product "Retail Convenience And Fuel Pos Software" | 2.8.1 Search vendor "Oracle" for product "Retail Convenience And Fuel Pos Software" and version "2.8.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Xstore Point Of Service Search vendor "Oracle" for product "Retail Xstore Point Of Service" | 7.0 Search vendor "Oracle" for product "Retail Xstore Point Of Service" and version "7.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Xstore Point Of Service Search vendor "Oracle" for product "Retail Xstore Point Of Service" | 7.1 Search vendor "Oracle" for product "Retail Xstore Point Of Service" and version "7.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Soa Suite Search vendor "Oracle" for product "Soa Suite" | 12.1.3.0.0 Search vendor "Oracle" for product "Soa Suite" and version "12.1.3.0.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Soa Suite Search vendor "Oracle" for product "Soa Suite" | 12.2.1.3.0 Search vendor "Oracle" for product "Soa Suite" and version "12.2.1.3.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Webcenter Portal Search vendor "Oracle" for product "Webcenter Portal" | 11.1.1.9.0 Search vendor "Oracle" for product "Webcenter Portal" and version "11.1.1.9.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Webcenter Portal Search vendor "Oracle" for product "Webcenter Portal" | 12.2.1.3.0 Search vendor "Oracle" for product "Webcenter Portal" and version "12.2.1.3.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Weblogic Server Search vendor "Oracle" for product "Weblogic Server" | 12.1.3.0.0 Search vendor "Oracle" for product "Weblogic Server" and version "12.1.3.0.0" | - |
Affected
| ||||||
Netapp Search vendor "Netapp" | Oncommand Workflow Automation Search vendor "Netapp" for product "Oncommand Workflow Automation" | - | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Virtualization Search vendor "Redhat" for product "Virtualization" | 4.2 Search vendor "Redhat" for product "Virtualization" and version "4.2" | - |
Affected
|