openSUSE-SU-2020:0607-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2020:0607-1.json
JSON Data
https://api.osv.dev/v1/vulns/openSUSE-SU-2020:0607-1
Related
Published
2020-05-03T16:19:33Z
Modified
2020-05-03T16:19:33Z
Summary
Security update for bouncycastle
Details

This update for bouncycastle fixes the following issues:

Version update to 1.60:

  • CVE-2018-1000613: Use of Externally-ControlledInput to Select Classes or Code (boo#1100694)

  • Release notes: http://www.bouncycastle.org/releasenotes.html

Version update to 1.59:

  • CVE-2017-13098: Fix against Bleichenbacher oracle when not using the lightweight APIs (boo#1072697).
  • Release notes: http://www.bouncycastle.org/releasenotes.html
References

Affected packages

openSUSE:Leap 15.1 / bouncycastle

Package

Name
bouncycastle
Purl
purl:rpm/suse/bouncycastle&distro=openSUSE%20Leap%2015.1

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.60-lp151.3.3.1

Ecosystem specific

{
    "binaries": [
        {
            "bouncycastle-javadoc": "1.60-lp151.3.3.1",
            "bouncycastle": "1.60-lp151.3.3.1"
        }
    ]
}