Re: Bouncy Castle Vulnerability VU#306792
"Eckenfels. Bernd" <[email protected]> Mon, 1 Apr 2019 16:18:54 +0000
| Newsgroups | gmane.comp.encryption.bouncy-castle.devel |
|---|---|
| Message-ID | <ED12D06EC205E3458FC3E23CD84D4ED50255256B28@dedcexch02.seeburger.de> |
The security note contains the answer: Starting with Bouncy Castle 1.47, which was released<https://www.bouncycastle.org/releasenotes.html> on March 30, 2012, the BKS keystore format was updated to version 2, which uses a 160-bit MAC. Starting with Bouncy Castle 1.49, optional support for the original keystore format was reintroduced, as "BKS-V1." “Don’t use “BKS-V1”, It cannot be fixed in code since the format of the file is the problem. (if it is a problem at all as integrity protection in keystores is questionable anyway) Gruss Bernd Von: Michael Ross <[email protected]> Gesendet: Montag, 1. April 2019 18:06 An: [email protected] Betreff: [dev-crypto] Bouncy Castle Vulnerability VU#306792 Hi, There is a Vulnerability Note VU#306792 "Bouncy Castle BKS-V1 keystore files vulnerable to trivial hash collisions" - see: https://www.kb.cert.org/vuls/id/306792/ Does anybody know if this issue fixed yet? If not fixed, are there any plans to fix it? Thanks, Michael Ross Senior Software Engineer, Zafin SEEBURGER AG Vorstand/SEEBURGER Executive Board: Sitz der Gesellschaft/Registered Office: Axel Haas, Michael Kleeberg, Axel Otto, Dr. Martin Kuntz, Matthias Feßenbecker Edisonstr. 1 D-75015 Bretten Vorsitzende des Aufsichtsrats/Chairperson of the SEEBURGER Supervisory Board: Tel.: 07252 / 96 - 0 Prof. Dr. Simone Zeuchner Fax: 07252 / 96 - 2222 Internet: http://www.seeburger.de Registergericht/Commercial Register: e-mail: [email protected] HRB 240708 Mannheim Dieses E-Mail ist nur für den Empfänger bestimmt, an den es gerichtet ist und kann vertrauliches bzw. unter das Berufsgeheimnis fallendes Material enthalten. Jegliche darin enthaltene Ansicht oder Meinungsäußerung ist die des Autors und stellt nicht notwendigerweise die Ansicht oder Meinung der SEEBURGER AG dar. Sind Sie nicht der Empfänger, so haben Sie diese E-Mail irrtümlich erhalten und jegliche Verwendung, Veröffentlichung, Weiterleitung, Abschrift oder jeglicher Druck dieser E-Mail ist strengstens untersagt. Weder die SEEBURGER AG noch der Absender (Eckenfels. Bernd) übernehmen die Haftung für Viren; es obliegt Ihrer Verantwortung, die E-Mail und deren Anhänge auf Viren zu prüfen. This email is intended only for the recipient(s) to whom it is addressed. This email may contain confidential material that may be protected by professional secrecy. Any fact or opinion contained, or expression of the material herein, does not necessarily reflect that of SEEBURGER AG. If you are not the addressee or if you have received this email in error, any use, publication or distribution including forwarding, copying or printing is strictly prohibited. Neither SEEBURGER AG, nor the sender (Eckenfels. Bernd) accept liability for viruses; it is your responsibility to check this email and its attachments for viruses.