V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2018-5382
DEB
Medium

The default BKS keystore use an HMAC that is only 16 bits long, which can allow an attacker to compromise the integrity of a BKS keystore. …

CVSS
5.1
Medium
EPSS
0.00
p17
Published
2018-01-01
Updated
2018-01-01
Description

The default BKS keystore use an HMAC that is only 16 bits long, which can allow an attacker to compromise the integrity of a BKS keystore. Bouncy Castle release 1.47 changes the BKS format to a format which uses a 160 bit HMAC instead. This applies to any BKS keystore generated prior to BC 1.47. For situations where people need to create the files for legacy reasons a specific keystore type "BKS-V1" was introduced in 1.49. It should be noted that the use of "BKS-V1" is discouraged by the library authors and should only be used where it is otherwise safe to do so, as in where the use of a 16 bit checksum for the file integrity check is not going to cause a security issue in itself.

Tags · CWE
Crypto
CWE-327
CAPEC-20
CAPEC-97
CAPEC-459
CAPEC-473
CAPEC-475
CAPEC-608
CAPEC-614
Affected products
SoappySoappyAnsiblerole-insights-clientAnsiblerole-insights-clientBouncycastleBouncycastleBouncycastleBouncycastleBouncycastleCandlepinCandlepinCreaterepo_cCreaterepo_cForemanForemanForeman-bootloaders-redhatForeman-bootloaders-redhatForeman-installerForeman-installerForeman-proxy
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Timeline
2018-01-01
Published
2018-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: L
Local (L)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: L
Low (L)
Integrity Impact
I: L
Low (L)
Availability Impact
A: N
None (N)
Exploit indicators
EPSS
0.003 · p17
Known exploited (KEV)
No
MITRE ATT&CK
Inferred via CAPEC
└ via CAPEC-473 · CWE-327
└ via CAPEC-473 · CWE-327
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
SOAPpyTracked
SOAPpyTracked
ansiblerole-insights-clientTracked
ansiblerole-insights-clientTracked
bouncycastleTracked
bouncycastleTracked
bouncycastleTracked
bouncycastleTracked
bouncycastleTracked
candlepinTracked
candlepinTracked
createrepo_cTracked
createrepo_cTracked
foremanTracked
foremanTracked
foreman-bootloaders-redhatTracked
foreman-bootloaders-redhatTracked
foreman-installerTracked
foreman-installerTracked
foreman-proxyTracked
Showing first 20 of 642
Source databases
DEB
CVE
RED
UBU