VDB

CVE-2016-1000343

CVE-2016-1000343 PUBLISHED

In the Bouncy Castle JCE Provider version 1.55 and earlier the DSA key pair generator generates a weak private key if used with default values. If the JCA key pair generator is not explicitly initialised with DSA parameters, 1.55 and earlier generates a private value assuming a 1024 bit key size. In earlier releases this can be dealt with by explicitly passing parameters to the key pair generator.

EPSS 1.07% · 78.1th percentile

Risk Scores

EPSS Score
1.07%
78.1th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSbouncycastle0, 1.48+dfsg-2, 1.49+dfsg-2
Ubuntu:16.04:LTSbouncycastle0, 1.49+dfsg-3ubuntu1, 1.51-4ubuntu1

Exploit Intelligence

…and 5 more exploits

Timeline

  • Jun 4, 2018 CVE Published
  • Feb 4, 2022 EPSS Score
  • Mar 29, 2022 EPSS Score
  • May 20, 2022 EPSS Score
  • Sep 3, 2022 EPSS Score
  • Oct 26, 2022 EPSS Score
  • Dec 18, 2022 EPSS Score
  • Feb 8, 2023 EPSS Score
  • Apr 2, 2023 EPSS Score
  • May 25, 2023 EPSS Score
  • Sep 7, 2023 EPSS Score
  • Oct 29, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›