Bouncy Castle BC 1.54 - 1.59, BC-FJA 1.0.0, BC-FJA 1.0.1 and earlier have a flaw in the Low-level interface to RSA key pair generator, specifically RSA Key Pairs generated in low-level API with added certainty may have less M-R tests than expected. This appears to be fixed in versions BC 1.60 beta 4 and later, BC-FJA 1.0.2 and later.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Bouncycastle
Subscribe
|
|
|
Debian
Subscribe
|
Debian Linux
Subscribe
|
|
Netapp
Subscribe
|
Oncommand Workflow Automation
Subscribe
|
|
Oracle
Subscribe
|
Api Gateway
Subscribe
Business Process Management Suite
Subscribe
Business Transaction Management
Subscribe
Communications Application Session Controller
Subscribe
Communications Converged Application Server
Subscribe
Communications Webrtc Session Controller
Subscribe
Enterprise Repository
Subscribe
Managed File Transfer
Subscribe
Peoplesoft Enterprise Peopletools
Subscribe
Retail Convenience And Fuel Pos Software
Subscribe
Retail Xstore Point Of Service
Subscribe
Soa Suite
Subscribe
Webcenter Portal
Subscribe
Weblogic Server
Subscribe
|
|
Redhat
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-4233-1 | bouncycastle security update |
EUVD |
EUVD-2018-0718 | Bouncy Castle has a flaw in the Low-level interface to RSA key pair generator |
Github GHSA |
GHSA-xqj7-j8j5-f2xr | Bouncy Castle has a flaw in the Low-level interface to RSA key pair generator |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 12 May 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Bouncycastle bc-java
|
|
| CPEs | cpe:2.3:a:bouncycastle:bc-java:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Bouncycastle legion-of-the-bouncy-castle-java-crytography-api
|
Bouncycastle bc-java
|
Fri, 23 Aug 2024 05:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:jboss_enterprise_application_platform:7.1::el7 |
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T12:33:49.372Z
Reserved: 2018-04-30T00:00:00
Link: CVE-2018-1000180
No data.
Status : Modified
Published: 2018-06-05T13:29:00.203
Modified: 2025-05-12T17:37:16.527
Link: CVE-2018-1000180
OpenCVE Enrichment
No data.
Debian DSA
EUVD
Github GHSA