An information disclosure vulnerability in Bouncy Castle could enable a local malicious application to gain access to user’s private information. Upstream bug: https://github.com/bcgit/bc-java/issues/177 References: https://source.android.com/security/bulletin/2016-01-01#information_disclosure_vulnerability_in_bouncy_castle
Created bouncycastle tracking bugs for this issue: Affects: epel-all [bug 1444025] Affects: fedora-24 [bug 1444024]
JBoss fuse ships bouncycastle version 1.54 in fabric8, camel and karaf container. To have the fix for this particular CVE users should update to version 1.56 or later.
This issue has been addressed in the following products: Red Hat JBoss Fuse Via RHSA-2017:1832 https://access.redhat.com/errata/RHSA-2017:1832
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 7.0.8 Via RHSA-2017:2810 https://access.redhat.com/errata/RHSA-2017:2810
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7 Via RHSA-2017:2808 https://access.redhat.com/errata/RHSA-2017:2808
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6 Via RHSA-2017:2809 https://access.redhat.com/errata/RHSA-2017:2809
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7 Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6 Via RHSA-2017:2811 https://access.redhat.com/errata/RHSA-2017:2811
This issue has been addressed in the following products: Red Hat Satellite 6.4 for RHEL 7 Via RHSA-2018:2927 https://access.redhat.com/errata/RHSA-2018:2927