CVE-2016-1000343
In Bouncy Castle JCE Provider the DSA key pair generator generates a weak private key if used with default values
7.5
HIGH
CVSS 3.1
EPSS 1.1%
Description
In the Bouncy Castle JCE Provider version 1.55 and earlier the DSA key pair generator generates a weak private key if used with default values. If the JCA key pair generator is not explicitly initialised with DSA parameters, 1.55 and earlier generates a private value assuming a 1024 bit key size. In earlier releases this can be dealt with by explicitly passing parameters to the key pair generator.
How to fix CVE-2016-1000343
To remediate CVE-2016-1000343, upgrade the affected package to a fixed version below.
- —upgrade to 1.56-1 or later
- —upgrade to 1.56 or later
- —upgrade to 1.56 or later
- —upgrade to 1.56 or later
Is CVE-2016-1000343 being exploited?
Low — EPSS is 1.1%, meaning exploitation activity has not been observed at scale.
Affected packages (4)
- from 0, < 1.56-1
- from 0, < 1.56
- from 0, < 1.56
- from 0, < 1.56
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |