Lack of data validation - Path Traversal In org.bouncycastle:bcprov-jdk14
Description
Bouncy Castle Has Covert Timing Channel Vulnerability Covert timing channel vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA core on all (core modules). This vulnerability is associated with program files FrodoEngine.Java.
This issue only affects users of the FrodoKEM algorithm involved in the decryption of encapsulations.
This issue affects BC-JAVA: from 1.71 to 1.80.1, 1.81, 1.82 to 1.83.
Fixed versions: 1.80.2, 1.81.1, 1.84
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
debian 12 | - | ||
debian 13 | - | ||
debian 14 | - | ||
maven | 1.81.1 | ||
maven | 1.84 | ||
maven | 1.80.2 |
Aliases
1. 2. 3. 4. 5. 6.
References
1. 2. 3. 4.