VDB

DEBIAN-CVE-2016-1000338

DEBIAN-CVE-2016-1000338 PUBLISHED CVSS 7.5 HIGH

In Bouncy Castle JCE Provider version 1.55 and earlier the DSA does not fully validate ASN.1 encoding of signature on verification. It is possible to inject extra elements in the sequence making up the signature and still have it validate, which in some cases may allow the introduction of 'invisible' data into a signed structure.

Risk Scores

CVSS v3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Affected Products

VendorProductVersions
Debian:14bouncycastle0, 0, 0
Debian:13bouncycastle0, 0, 0
Debian:12bouncycastle0, 0, 0
Debian:11bouncycastle0, 0, 0

Timeline

  • Jun 1, 2018 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›