USN-3727-1: Bouncy Castle vulnerabilities
1 August 2018
Several security issues were fixed in Bouncy Castle.
Releases
Packages
- bouncycastle - Java implementation of cryptographic algorithms
Details
It was discovered that Bouncy Castle incorrectly handled certain crypto
algorithms. A remote attacker could possibly use these issues to obtain
sensitive information, including private keys.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 14.04
-
libbcmail-java
-
1.49+dfsg-2ubuntu0.1
-
libbcpg-java
-
1.49+dfsg-2ubuntu0.1
-
libbcpkix-java
-
1.49+dfsg-2ubuntu0.1
-
libbcprov-java
-
1.49+dfsg-2ubuntu0.1
In general, a standard system update will make all the necessary changes.