漏洞信息详情
Bouncy Castle BC 竞争条件问题漏洞
漏洞简介
Bouncy Castle BC是Bouncy Castle组织的一个用于C#和Java应用程序的加密库。
Bouncy Castle BC Java, BC C# .NET, BC-FJA, BC-FNA 存在竞争条件问题漏洞,攻击者可利用该漏洞绕过对数据的访问限制,以获取敏感信息。
漏洞公告
目前厂商暂未发布修复措施解决此安全问题,建议使用此软件的用户随时关注厂商主页或参考网址以获取解决办法:
https://github.com/LINBIT/csync2/commit/416f1de878ef97e27e27508914f7ba8599a0be22
参考网址
来源:CONFIRM
链接:https://security.netapp.com/advisory/ntap-20210622-0007/
来源:MISC
链接:https://github.com/bcgit/bc-csharp/wiki/CVE-2020-15522
来源:MISC
链接:https://github.com/bcgit/bc-java/wiki/CVE-2020-15522
来源:MISC
链接:https://www.bouncycastle.org/releasenotes.html
来源:access.redhat.com
链接:https://access.redhat.com/security/cve/cve-2020-15522
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.2245
来源:www.ibm.com
链接:https://www.ibm.com/support/pages/node/6485147
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.2416
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/163517/Red-Hat-Security-Advisory-2021-2755-01.html
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2021072033
来源:vigilance.fr
链接:https://vigilance.fr/vulnerability/Bouncy-Castle-Java-Cryptography-Extension-information-disclosure-via-ECC-GCD-Based-Inversion-Side-channel-35494
受影响实体
暂无
补丁
暂无
还没有评论,来说两句吧...