Bugzilla will be upgraded to version 5.0 on a still to be determined date in the near future. The original upgrade date has been delayed.
Bug 1588306 - (CVE-2018-1000180) CVE-2018-1000180 bouncycastle: flaw in the low-level interface to RSA key pair generator
CVE-2018-1000180 bouncycastle: flaw in the low-level interface to RSA key pai...
Status: NEW
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
medium Severity medium
: ---
: ---
Assigned To: Red Hat Product Security
impact=moderate,public=20180418,repor...
: Security
Depends On: 1588307 1588309 1589564 1589565 1592662 1588308 1592655
Blocks: 1588310
  Show dependency treegraph
 
Reported: 2018-06-07 01:11 EDT by Sam Fowler
Modified: 2018-10-25 11:42 EDT (History)
67 users (show)

See Also:
Fixed In Version: bouncycastle 1.60beta4
Doc Type: If docs needed, set a value
Doc Text:
A vulnerability was found in BouncyCastle. The number of iterations of the Miller-Rabin primality test was incorrectly calculated (according to FIPS 186-4 C.3). Under some circumstances, this could lead to the generation of weak RSA key pairs.
Story Points: ---
Clone Of:
Environment:
Last Closed:
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2018:2423 None None None 2018-08-15 07:31 EDT
Red Hat Product Errata RHSA-2018:2424 None None None 2018-08-15 07:33 EDT
Red Hat Product Errata RHSA-2018:2425 None None None 2018-08-15 07:20 EDT
Red Hat Product Errata RHSA-2018:2428 None None None 2018-08-15 07:30 EDT
Red Hat Product Errata RHSA-2018:2643 None None None 2018-09-04 09:46 EDT
Red Hat Product Errata RHSA-2018:2669 None None None 2018-09-11 03:56 EDT

  None (edit)
Description Sam Fowler 2018-06-07 01:11:22 EDT
Bouncy Castle BC 1.54 - 1.59, BC-FJA 1.0.0, BC-FJA 1.0.1 and earlier have a flaw in the Low-level interface to RSA key pair generator, specifically RSA Key Pairs generated in low-level API with added certainty may have less M-R tests than expected. This appears to be fixed in versions BC 1.60 beta 4 and later, BC-FJA 1.0.2 and later.


Upstream Issue:

https://www.bouncycastle.org/jira/browse/BJA-694


Upstream Commits:

https://github.com/bcgit/bc-java/commit/22467b6e8fe19717ecdf201c0cf91bacf04a55ad
https://github.com/bcgit/bc-java/commit/73780ac522b7795fc165630aba8d5f5729acc839
Comment 1 Sam Fowler 2018-06-07 01:12:18 EDT
Created bouncycastle tracking bugs for this issue:

Affects: epel-all [bug 1588307]
Affects: fedora-all [bug 1588308]
Comment 6 Kurt Seifried 2018-06-10 16:28:33 EDT
Statement:

This issue affects the versions of bouncycastle as shipped with Red Hat Subscription Asset Manager 1.x. Red Hat Product Security has rated this issue as having a security impact of Moderate. No update is planned for this product at this time. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Comment 9 errata-xmlrpc 2018-08-15 07:20:17 EDT
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform

Via RHSA-2018:2425 https://access.redhat.com/errata/RHSA-2018:2425
Comment 10 errata-xmlrpc 2018-08-15 07:29:59 EDT
This issue has been addressed in the following products:

  Red Hat Single Sign-On 7.2.4 zip

Via RHSA-2018:2428 https://access.redhat.com/errata/RHSA-2018:2428
Comment 11 errata-xmlrpc 2018-08-15 07:31:16 EDT
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6

Via RHSA-2018:2423 https://access.redhat.com/errata/RHSA-2018:2423
Comment 12 errata-xmlrpc 2018-08-15 07:33:08 EDT
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7

Via RHSA-2018:2424 https://access.redhat.com/errata/RHSA-2018:2424
Comment 14 errata-xmlrpc 2018-09-04 09:45:50 EDT
This issue has been addressed in the following products:

  Red Hat Virtualization 4 for Red Hat Enterprise Linux 7

Via RHSA-2018:2643 https://access.redhat.com/errata/RHSA-2018:2643
Comment 15 errata-xmlrpc 2018-09-11 03:55:41 EDT
This issue has been addressed in the following products:

  Red Hat JBoss Fuse

Via RHSA-2018:2669 https://access.redhat.com/errata/RHSA-2018:2669

Note You need to log in before you can comment on or make changes to this bug.