CVE-2018-1000613

Impact:
Moderate
Public Date:
2018-03-03
CWE:
CWE-470
Bugzilla:
1601096: CVE-2018-1000613 bouncycastle: lack of class checking in deserialization of XMSS/XMSS^MT private keys with BDS state information

The MITRE CVE dictionary describes this issue as:

Legion of the Bouncy Castle Legion of the Bouncy Castle Java Cryptography APIs version prior to version 1.60 contains a CWE-470: Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in XMSS/XMSS^MT private key deserialization that can result in Deserializing an XMSS/XMSS^MT private key can result in the execution of unexpected code.. This attack appear to be exploitable via A handcrafted private key can include references to unexpected classes which will be picked up from the class path for the executing application.. This vulnerability appears to have been fixed in 1.60 and later.

Find out more about CVE-2018-1000613 from the MITRE CVE dictionary dictionary and NIST NVD.

Statement

The XMSS/XMSS^MT algorithms were first introduced in upstream bouncycastle version 1.57. Versions prior to this, that have not had the new algorithms back-ported, are not affected.

CVSS v3 metrics

NOTE: The following CVSS v3 metrics and score provided are preliminary and subject to review.

CVSS3 Base Score 4.9
CVSS3 Base Metrics CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
Attack Vector Local
Attack Complexity High
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality Low
Integrity Impact Low
Availability Impact Low

Affected Packages State

Platform Package State
Red Hat Virtualization 4 eap7-bouncycastle Not affected
Red Hat Subscription Asset Manager 1 bouncycastle Not affected
Red Hat Software Collections for Red Hat Enterprise Linux rh-eclipse46-bouncycastle Not affected
Red Hat Satellite 6 bouncycastle Not affected
Red Hat JBoss Fuse 7 jclouds-bouncycastle Under investigation
Red Hat JBoss Fuse 6 jclouds-bouncycastle Under investigation
Red Hat JBoss EAP 7 bouncycastle Not affected
Red Hat JBoss Data Virtualization 6 bouncycastle Under investigation

Last Modified

CVE description copyright © 2017, The MITRE Corporation

Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.