In the Bouncy Castle JCE Provider version 1.55 and earlier the DSA key pair generator generates a weak private key if used with default values. If the JCA key pair generator is not explicitly initialised with DSA parameters, 1.55 and earlier generates a private value assuming a 1024 bit key size. In earlier releases this can be dealt with by explicitly passing parameters to the key pair generator.
References
Configurations
History
12 May 2025, 17:37
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:bouncycastle:bc-java:*:*:*:*:*:*:*:* | |
First Time |
Bouncycastle bc-java
|
Information
Published : 2018-06-04 13:29
Updated : 2025-05-12 17:37
NVD link : CVE-2016-1000343
Mitre link : CVE-2016-1000343
CVE.ORG link : CVE-2016-1000343
JSON object : View
Products Affected
bouncycastle
- bc-java
debian
- debian_linux
CWE
CWE-310
Cryptographic Issues