Bouncy Castle BC Java before 1.66, BC C# .NET before 1.8.7, BC-FJA before 1.0.1.2, 1.0.2.1, and BC-FNA before 1.0.1.1 have a timing issue within the EC math library that can expose information about the private key when an attacker is able to observe timing information for the generation of multiple deterministic ECDSA signatures.
References
Link | Resource |
---|---|
https://github.com/bcgit/bc-csharp/wiki/CVE-2020-15522 | Third Party Advisory |
https://github.com/bcgit/bc-java/wiki/CVE-2020-15522 | Third Party Advisory |
https://security.netapp.com/advisory/ntap-20210622-0007/ | |
https://www.bouncycastle.org/releasenotes.html | Release Notes Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2021-05-20T11:20:18
Updated: 2021-06-22T08:06:30
Reserved: 2020-07-04T00:00:00
Link: CVE-2020-15522
JSON object: View
NVD Information
Status : Modified
Published: 2021-05-20T12:15:08.003
Modified: 2021-06-22T09:15:11.800
Link: CVE-2020-15522
JSON object: View
Redhat Information
No data.
CWE