CVE-2018-1000180
bouncycastle: flaw in the low-level interface to RSA key pair generator
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Bouncy Castle BC 1.54 - 1.59, BC-FJA 1.0.0, BC-FJA 1.0.1 and earlier have a flaw in the Low-level interface to RSA key pair generator, specifically RSA Key Pairs generated in low-level API with added certainty may have less M-R tests than expected. This appears to be fixed in versions BC 1.60 beta 4 and later, BC-FJA 1.0.2 and later.
Bouncy Castle BC 1.54 - 1.59, BC-FJA 1.0.0, BC-FJA 1.0.1 y anteriores tiene un vulnerabilidad en la interfaz de bajo nivel del generador de claves RSA; específicamente, los pares de claves RSA generados en la API de bajo nivel con un valor certainty añadido pueden tener menos tests M-R de lo esperado. Parece que se ha resuelto en versiones BC 1.60 beta 4 y posteriores y BC-FJA 1.0.2 y posteriores.
A vulnerability was found in BouncyCastle. The number of iterations of the Miller-Rabin primality test was incorrectly calculated (according to FIPS 186-4 C.3). Under some circumstances, this could lead to the generation of weak RSA key pairs.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-04-30 CVE Reserved
- 2018-06-05 CVE Published
- 2024-07-31 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-325: Missing Cryptographic Step
- CWE-327: Use of a Broken or Risky Cryptographic Algorithm
CAPEC
References (23)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/106567 | Third Party Advisory | |
https://github.com/bcgit/bc-java/wiki/CVE-2018-1000180 | X_refsource_misc | |
https://lists.apache.org/thread.html/708d94141126eac03011144a971a6411fcac16d9c248d1d535a39451%40%3Csolr-user.lucene.apache.org%3E | Mailing List | |
https://www.bountysource.com/issues/58293083-rsa-key-generation-computation-of-iterations-for-mr-primality-test | Third Party Advisory | |
https://www.oracle.com/security-alerts/cpuApr2021.html | X_refsource_misc | |
https://www.oracle.com/security-alerts/cpuapr2020.html | X_refsource_misc | |
https://www.oracle.com/security-alerts/cpuoct2020.html | X_refsource_misc | |
https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html | X_refsource_misc |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://access.redhat.com/errata/RHSA-2018:2423 | 2023-11-07 | |
https://access.redhat.com/errata/RHSA-2018:2424 | 2023-11-07 | |
https://access.redhat.com/errata/RHSA-2018:2425 | 2023-11-07 | |
https://access.redhat.com/errata/RHSA-2018:2428 | 2023-11-07 | |
https://access.redhat.com/errata/RHSA-2018:2643 | 2023-11-07 | |
https://access.redhat.com/errata/RHSA-2018:2669 | 2023-11-07 | |
https://access.redhat.com/errata/RHSA-2019:0877 | 2023-11-07 | |
https://www.debian.org/security/2018/dsa-4233 | 2023-11-07 | |
https://access.redhat.com/security/cve/CVE-2018-1000180 | 2019-04-24 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1588306 | 2019-04-24 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Redhat Search vendor "Redhat" | Jboss Enterprise Application Platform Search vendor "Redhat" for product "Jboss Enterprise Application Platform" | 7.1.0 Search vendor "Redhat" for product "Jboss Enterprise Application Platform" and version "7.1.0" | - |
Affected
| in | Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 6.0 Search vendor "Redhat" for product "Enterprise Linux" and version "6.0" | - |
Safe
|
Redhat Search vendor "Redhat" | Jboss Enterprise Application Platform Search vendor "Redhat" for product "Jboss Enterprise Application Platform" | 7.1.0 Search vendor "Redhat" for product "Jboss Enterprise Application Platform" and version "7.1.0" | - |
Affected
| in | Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 7.0 Search vendor "Redhat" for product "Enterprise Linux" and version "7.0" | - |
Safe
|
Bouncycastle Search vendor "Bouncycastle" | Fips Java Api Search vendor "Bouncycastle" for product "Fips Java Api" | <= 1.0.1 Search vendor "Bouncycastle" for product "Fips Java Api" and version " <= 1.0.1" | - |
Affected
| ||||||
Bouncycastle Search vendor "Bouncycastle" | Legion-of-the-bouncy-castle-java-crytography-api Search vendor "Bouncycastle" for product "Legion-of-the-bouncy-castle-java-crytography-api" | >= 1.54 <= 1.59 Search vendor "Bouncycastle" for product "Legion-of-the-bouncy-castle-java-crytography-api" and version " >= 1.54 <= 1.59" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 9.0 Search vendor "Debian" for product "Debian Linux" and version "9.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Api Gateway Search vendor "Oracle" for product "Api Gateway" | 11.1.2.4.0 Search vendor "Oracle" for product "Api Gateway" and version "11.1.2.4.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Business Process Management Suite Search vendor "Oracle" for product "Business Process Management Suite" | 11.1.1.9.0 Search vendor "Oracle" for product "Business Process Management Suite" and version "11.1.1.9.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Business Process Management Suite Search vendor "Oracle" for product "Business Process Management Suite" | 12.1.3.0.0 Search vendor "Oracle" for product "Business Process Management Suite" and version "12.1.3.0.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Business Process Management Suite Search vendor "Oracle" for product "Business Process Management Suite" | 12.2.1.3.0 Search vendor "Oracle" for product "Business Process Management Suite" and version "12.2.1.3.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Business Transaction Management Search vendor "Oracle" for product "Business Transaction Management" | 12.1.0 Search vendor "Oracle" for product "Business Transaction Management" and version "12.1.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Application Session Controller Search vendor "Oracle" for product "Communications Application Session Controller" | 3.7.1 Search vendor "Oracle" for product "Communications Application Session Controller" and version "3.7.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Application Session Controller Search vendor "Oracle" for product "Communications Application Session Controller" | 3.8.0 Search vendor "Oracle" for product "Communications Application Session Controller" and version "3.8.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Converged Application Server Search vendor "Oracle" for product "Communications Converged Application Server" | < 7.0.0.1 Search vendor "Oracle" for product "Communications Converged Application Server" and version " < 7.0.0.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Webrtc Session Controller Search vendor "Oracle" for product "Communications Webrtc Session Controller" | < 7.2 Search vendor "Oracle" for product "Communications Webrtc Session Controller" and version " < 7.2" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Enterprise Repository Search vendor "Oracle" for product "Enterprise Repository" | 12.1.3.0.0 Search vendor "Oracle" for product "Enterprise Repository" and version "12.1.3.0.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Managed File Transfer Search vendor "Oracle" for product "Managed File Transfer" | 12.1.3.0.0 Search vendor "Oracle" for product "Managed File Transfer" and version "12.1.3.0.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Managed File Transfer Search vendor "Oracle" for product "Managed File Transfer" | 12.2.1.3.0 Search vendor "Oracle" for product "Managed File Transfer" and version "12.2.1.3.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Peoplesoft Enterprise Peopletools Search vendor "Oracle" for product "Peoplesoft Enterprise Peopletools" | 8.55 Search vendor "Oracle" for product "Peoplesoft Enterprise Peopletools" and version "8.55" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Peoplesoft Enterprise Peopletools Search vendor "Oracle" for product "Peoplesoft Enterprise Peopletools" | 8.56 Search vendor "Oracle" for product "Peoplesoft Enterprise Peopletools" and version "8.56" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Peoplesoft Enterprise Peopletools Search vendor "Oracle" for product "Peoplesoft Enterprise Peopletools" | 8.57 Search vendor "Oracle" for product "Peoplesoft Enterprise Peopletools" and version "8.57" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Convenience And Fuel Pos Software Search vendor "Oracle" for product "Retail Convenience And Fuel Pos Software" | 2.8.1 Search vendor "Oracle" for product "Retail Convenience And Fuel Pos Software" and version "2.8.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Xstore Point Of Service Search vendor "Oracle" for product "Retail Xstore Point Of Service" | 7.0 Search vendor "Oracle" for product "Retail Xstore Point Of Service" and version "7.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Xstore Point Of Service Search vendor "Oracle" for product "Retail Xstore Point Of Service" | 7.1 Search vendor "Oracle" for product "Retail Xstore Point Of Service" and version "7.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Soa Suite Search vendor "Oracle" for product "Soa Suite" | 12.1.3.0.0 Search vendor "Oracle" for product "Soa Suite" and version "12.1.3.0.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Soa Suite Search vendor "Oracle" for product "Soa Suite" | 12.2.1.3.0 Search vendor "Oracle" for product "Soa Suite" and version "12.2.1.3.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Webcenter Portal Search vendor "Oracle" for product "Webcenter Portal" | 11.1.1.9.0 Search vendor "Oracle" for product "Webcenter Portal" and version "11.1.1.9.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Webcenter Portal Search vendor "Oracle" for product "Webcenter Portal" | 12.2.1.3.0 Search vendor "Oracle" for product "Webcenter Portal" and version "12.2.1.3.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Weblogic Server Search vendor "Oracle" for product "Weblogic Server" | 12.1.3.0.0 Search vendor "Oracle" for product "Weblogic Server" and version "12.1.3.0.0" | - |
Affected
| ||||||
Netapp Search vendor "Netapp" | Oncommand Workflow Automation Search vendor "Netapp" for product "Oncommand Workflow Automation" | - | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Virtualization Search vendor "Redhat" for product "Virtualization" | 4.2 Search vendor "Redhat" for product "Virtualization" and version "4.2" | - |
Affected
|