Bouncy Castle Vulnerability VU#306792

Michael Ross <[email protected]> Mon, 1 Apr 2019 12:05:56 -0400
Newsgroups gmane.comp.encryption.bouncy-castle.devel
Message-ID <CACnAERmQ0rznVk44mVCO=9OneMf3kWzyzAXr_wjY=932TDaRQQ@mail.gmail.com>
Hi,

There is a Vulnerability Note VU#306792 "Bouncy Castle BKS-V1 keystore
files vulnerable to trivial hash collisions" - see:
https://www.kb.cert.org/vuls/id/306792/

Does anybody know if this issue fixed yet? If not fixed, are there any
plans to fix it?

Thanks,

Michael Ross
Senior Software Engineer, Zafin