Bug 1588314 (CVE-2016-1000344)

Summary: CVE-2016-1000344 bouncycastle: DHIES implementation allowed the use of ECB mode
Product: [Other] Security Response Reporter: Sam Fowler <sfowler>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: avibelli, bcourt, bgeorges, bkearney, bmaxwell, bmcclain, cbillett, cdewolf, chazlett, csutherl, darran.lofthouse, dblechte, dimitris, dosoudil, drieden, eedri, hhorak, jawilson, jbalunas, jjohnstn, jmatthew, jolee, jorton, jpallich, jschatte, jshepherd, jstastny, krathod, lgao, lthon, mgoldboi, michal.skrivanek, mmccune, mrike, mszynkie, myarboro, ohadlevy, pdrozd, pgallagh, pgier, psakar, pslavice, psotirop, puntogil, rchan, rgrunber, rnetuka, rruss, rsvoboda, sbonazzo, sherold, steve.traylen, sthorger, tomckay, trogers, tsanders, twalsh, vhalbert, vtunka, ykaul
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: bouncycastle 1.56 Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2019-06-10 10:27:30 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Bug Depends On: 1588321, 1589570, 1589571, 1592662, 1700955    
Bug Blocks: 1588310    

Description Sam Fowler 2018-06-07 05:22:48 UTC
In the Bouncy Castle JCE Provider version 1.55 and earlier the DHIES implementation allowed the use of ECB mode. This mode is regarded as unsafe and support for it has been removed from the provider.


Upstream Commits:

https://github.com/bcgit/bc-java/commit/9385b0ebd277724b167fe1d1456e3c112112be1f

Comment 1 Sam Fowler 2018-06-07 05:30:30 UTC
Created bouncycastle tracking bugs for this issue:

Affects: epel-6 [bug 1588321]

Comment 4 Kurt Seifried 2018-06-10 20:28:46 UTC
Statement:

This issue affects the versions of bouncycastle as shipped with Red Hat Subscription Asset Manager 1.x. Red Hat Product Security has rated this issue as having a security impact of Moderate. No update is planned for this product at this time. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.

Comment 6 errata-xmlrpc 2018-09-11 07:56:00 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Fuse

Via RHSA-2018:2669 https://access.redhat.com/errata/RHSA-2018:2669

Comment 7 errata-xmlrpc 2018-10-16 15:23:16 UTC
This issue has been addressed in the following products:

  Red Hat Satellite 6.4 for RHEL 7

Via RHSA-2018:2927 https://access.redhat.com/errata/RHSA-2018:2927