VDB

DEBIAN-CVE-2016-1000342

DEBIAN-CVE-2016-1000342 PUBLISHED CVSS 7.5 HIGH

In the Bouncy Castle JCE Provider version 1.55 and earlier ECDSA does not fully validate ASN.1 encoding of signature on verification. It is possible to inject extra elements in the sequence making up the signature and still have it validate, which in some cases may allow the introduction of 'invisible' data into a signed structure.

Risk Scores

CVSS 3.0
7.5
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Affected Products

VendorProductVersions
Debian:11bouncycastle0, 0, 0
Debian:14bouncycastle0, 0, 0
Debian:12bouncycastle0, 0, 0
Debian:13bouncycastle0, 0, 0

Exploit Intelligence

Timeline

  • Jun 4, 2018 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›