CVE-2016-1000352 PUBLISHED

In the Bouncy Castle JCE Provider version 1.55 and earlier the ECIES implementation allowed the use of ECB mode. This mode is regarded as unsafe and support for it has been removed from the provider.

EPSS 0.39% · 59.7th percentile

Risk Scores

EPSS Score
0.39%
59.7th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSbouncycastle0, 1.49+dfsg-3ubuntu1, 1.51-4ubuntu1

Timeline

References

Open in Interactive Console →