PublicDateAtUSN: 2018-06-04 Candidate: CVE-2016-1000343 PublicDate: 2018-06-04 13:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1000343 https://ubuntu.com/security/notices/USN-3727-1 Description: In the Bouncy Castle JCE Provider version 1.55 and earlier the DSA key pair generator generates a weak private key if used with default values. If the JCA key pair generator is not explicitly initialised with DSA parameters, 1.55 and earlier generates a private value assuming a 1024 bit key size. In earlier releases this can be dealt with by explicitly passing parameters to the key pair generator. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N [7.5 HIGH] Patches_bouncycastle: upstream: https://github.com/bcgit/bc-java/commit/50a53068c094d6cff37659da33c9b4505becd389 upstream_bouncycastle: released (1.56-1) precise/esm_bouncycastle: DNE trusty_bouncycastle: released (1.49+dfsg-2ubuntu0.1) trusty/esm_bouncycastle: DNE (trusty was released [1.49+dfsg-2ubuntu0.1]) xenial_bouncycastle: ignored (end of standard support, was needed) artful_bouncycastle: not-affected (1.57-1) bionic_bouncycastle: not-affected (1.59-1) cosmic_bouncycastle: not-affected (1.60-1) disco_bouncycastle: not-affected (1.60-1) eoan_bouncycastle: not-affected (1.60-1) focal_bouncycastle: not-affected (1.60-1) groovy_bouncycastle: not-affected (1.60-1) hirsute_bouncycastle: not-affected (1.60-1) impish_bouncycastle: not-affected (1.60-1) jammy_bouncycastle: not-affected (1.60-1) devel_bouncycastle: not-affected (1.60-1)