USN-3727-1: Bouncy Castle vulnerabilities
Publication date
1 August 2018
Overview
Several security issues were fixed in Bouncy Castle.
Releases
Packages
- bouncycastle - Java implementation of cryptographic algorithms
Details
It was discovered that Bouncy Castle incorrectly handled certain crypto
algorithms. A remote attacker could possibly use these issues to obtain
sensitive information, including private keys.
It was discovered that Bouncy Castle incorrectly handled certain crypto
algorithms. A remote attacker could possibly use these issues to obtain
sensitive information, including private keys.
Update instructions
In general, a standard system update will make all the necessary changes.
Learn more about how to get the fixes.The problem can be corrected by updating your system to the following package versions:
Ubuntu Release | Package Version | ||
---|---|---|---|
14.04 trusty | libbcmail-java – 1.49+dfsg-2ubuntu0.1 | ||
libbcpg-java – 1.49+dfsg-2ubuntu0.1 | |||
libbcpkix-java – 1.49+dfsg-2ubuntu0.1 | |||
libbcprov-java – 1.49+dfsg-2ubuntu0.1 |
Reduce your security exposure
Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.