Vulnerability Bulletins

DSA-3417 bouncycastle - security update

   
Affected software Debian
 
Tibor Jager, Jörg Schwenk, and Juraj Somorovsky, from Horst GörtzInstitute for IT Security, published a paper in ESORICS 2015 where theydescribe an invalid curve attack in Bouncy Castle Crypto, a Java libraryfor cryptography. An attacker is able to recover private Elliptic Curvekeys from different applications, for example, TLS servers.

More info:

https://www.debian.org/security/2015/dsa-3417