Debian Security Advisory
DLA-2433-1 bouncycastle -- LTS security update
- Date Reported:
- 05 Nov 2020
- Affected Packages:
- Security database references:
- In Mitre's CVE dictionary: CVE-2020-26939.
- More information:
It was discovered that there was an issue in the bouncycastle crypto library where attackers could obtain sensitive information due to observable differences in its response to invalid input.
In Legion of the Bouncy Castle BC before 1.55 and BC-FJA before 18.104.22.168, attackers can obtain sensitive information about a private exponent because of Observable Differences in Behavior to Error Inputs. This occurs in org.bouncycastle.crypto.encodings.OAEPEncoding. Sending invalid ciphertext that decrypts to a short payload in the OAEP Decoder could result in the throwing of an early exception, potentially leaking some information about the private exponent of the RSA private key performing the encryption.
For Debian 9
Stretch, these problems have been fixed in version 1.56-1+deb9u3.
We recommend that you upgrade your bouncycastle packages.
Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS