Re: Bouncy Castle Vulnerability VU#306792
Michael Ross <[email protected]> Mon, 1 Apr 2019 12:51:33 -0400
| Newsgroups | gmane.comp.encryption.bouncy-castle.devel |
|---|---|
| Message-ID | <CACnAERk_4z_EVFqTKX0FbWgaa7=h1pHXYepyLRnHogaJuiH+hQ@mail.gmail.com> |
Hello Bernd, Thanks for the promt answer. So, do you mean that starting with Bouncy Castle 1.47 both "BKS-V1" and (not sure) "BKS-V2" are supported? So, the Vulnerability Note VU#306792 is not exactly correct, or at least should not have high severiry? Please confirm. Thanks, Michael On Mon, Apr 1, 2019 at 12:19 PM Eckenfels. Bernd <[email protected]> wrote: > The security note contains the answer: > > > > Starting with Bouncy Castle 1.47, which was released > <https://www.bouncycastle.org/releasenotes.html> on March 30, 2012, the > BKS keystore format was updated to version 2, which uses a 160-bit MAC. > Starting with Bouncy Castle 1.49, optional support for the original > keystore format was reintroduced, as "BKS-V1." > > > > “Don’t use “BKS-V1”, It cannot be fixed in code since the format of the > file is the problem. (if it is a problem at all as integrity protection in > keystores is questionable anyway) > > > > Gruss > > Bernd > > > > *Von:* Michael Ross <[email protected]> > *Gesendet:* Montag, 1. April 2019 18:06 > *An:* [email protected] > *Betreff:* [dev-crypto] Bouncy Castle Vulnerability VU#306792 > > > > Hi, > > > > There is a Vulnerability Note VU#306792 "Bouncy Castle BKS-V1 keystore > files vulnerable to trivial hash collisions" - see: > > https://www.kb.cert.org/vuls/id/306792/ > > > > Does anybody know if this issue fixed yet? If not fixed, are there any > plans to fix it? > > > > Thanks, > > > > Michael Ross > > Senior Software Engineer, Zafin > > > > > > > > > > > > *SEEBURGER AG* Vorstand/SEEBURGER Executive Board: > Sitz der Gesellschaft/Registered Office: Axel Haas, Michael Kleeberg, > Axel Otto, Dr. Martin Kuntz, Matthias Feßenbecker > Edisonstr. 1 > D-75015 Bretten Vorsitzende des Aufsichtsrats/Chairperson of the > SEEBURGER Supervisory Board: > Tel.: 07252 / 96 - 0 Prof. Dr. Simone Zeuchner > Fax: 07252 / 96 - 2222 > Internet: http://www.seeburger.de Registergericht/Commercial Register: > e-mail: [email protected] HRB 240708 Mannheim > > > Dieses E-Mail ist nur für den Empfänger bestimmt, an den es gerichtet ist > und kann vertrauliches bzw. unter das Berufsgeheimnis fallendes Material > enthalten. Jegliche darin enthaltene Ansicht oder Meinungsäußerung ist die > des Autors und stellt nicht notwendigerweise die Ansicht oder Meinung der > SEEBURGER AG dar. Sind Sie nicht der Empfänger, so haben Sie diese E-Mail > irrtümlich erhalten und jegliche Verwendung, Veröffentlichung, > Weiterleitung, Abschrift oder jeglicher Druck dieser E-Mail ist strengstens > untersagt. Weder die SEEBURGER AG noch der Absender (Eckenfels. Bernd) > übernehmen die Haftung für Viren; es obliegt Ihrer Verantwortung, die > E-Mail und deren Anhänge auf Viren zu prüfen. > > This email is intended only for the recipient(s) to whom it is addressed. > This email may contain confidential material that may be protected by > professional secrecy. Any fact or opinion contained, or expression of the > material herein, does not necessarily reflect that of SEEBURGER AG. If you > are not the addressee or if you have received this email in error, any use, > publication or distribution including forwarding, copying or printing is > strictly prohibited. Neither SEEBURGER AG, nor the sender (Eckenfels. > Bernd) accept liability for viruses; it is your responsibility to check > this email and its attachments for viruses. > > -- Michael Ross Senior Software Engineer, Zafin [email protected] | O : 613-216-2504 Zafin - Canada http://zafin.com <http://zafin.com/>