VDB
DEBIAN-CVE-2016-1000345
DEBIAN-CVE-2016-1000345
PUBLISHED
CVSS 5.900000095367432 MEDIUM
In the Bouncy Castle JCE Provider version 1.55 and earlier the DHIES/ECIES CBC mode vulnerable to padding oracle attack. For BC 1.55 and older, in an environment where timings can be easily observed, it is possible with enough observations to identify when the decryption is failing due to padding.
Risk Scores
CVSS 3.0
5.900000095367432
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Debian:11 | bouncycastle | 0, 0, 0 |
| Debian:12 | bouncycastle | 0, 0, 0 |
| Debian:14 | bouncycastle | 0, 0, 0 |
| Debian:13 | bouncycastle | 0, 0, 0 |
Exploit Intelligence
- releasenotes.html (github-poc)
Timeline
- Jun 4, 2018 CVE Published
- Apr 28, 2026 CVE Updated