Bug 967521

Summary: VUL-0: CVE-2015-7575: bouncycastle: add validation that signature algorithm received in DigitallySigned structures is actually one of those offered
Product: [Novell Products] SUSE Security Incidents Reporter: boo35 boo35 <9b3e05a5>
Component: IncidentsAssignee: Security Team bot <security-team>
Status: RESOLVED FIXED QA Contact: Security Team bot <security-team>
Severity: Normal    
Priority: P5 - None CC: astieger, security-team, tchvatal
Version: unspecified   
Target Milestone: unspecified   
Hardware: Other   
OS: openSUSE 42.1   
Whiteboard:
Found By: --- Services Priority:
Business Priority: Blocker: ---
Marketing QA Status: --- IT Deployment: ---
Bug Depends on:    
Bug Blocks: 960996    

Description boo35 boo35 2016-02-20 01:16:12 UTC
per 

https://www.bouncycastle.org/latest_releases.html

"...
Latest Java Releases
Release 1.54 is now available for download.
This is primarily a security release concerning (D)TLS 1.2. Motivated by CVE-2015-7575
..."
Comment 1 Tomáš Chvátal 2016-02-20 08:46:05 UTC
Updated packages submitted to 13.2 Leap 42.1 and Factory.
Comment 2 Bernhard Wiedemann 2016-02-20 09:00:10 UTC
This is an autogenerated message for OBS integration:
This bug (967521) was mentioned in
https://build.opensuse.org/request/show/360600 Factory / bouncycastle
https://build.opensuse.org/request/show/360603 42.1+13.2 / bouncycastle
Comment 3 Andreas Stieger 2016-02-20 16:27:21 UTC
Moving to security incidents.

Additionally, for openSUSE Leap 42.1, we will fork this package from the  SUSE:SLE-12:GA codestream as it is not maintained in any product there.
Comment 4 Andreas Stieger 2016-02-20 16:28:08 UTC
Got https://build.opensuse.org/request/show/360603 for 13.2, 42.1
Comment 5 Andreas Stieger 2016-02-28 21:24:22 UTC
Released
Comment 6 Swamp Workflow Management 2016-02-29 01:12:02 UTC
openSUSE-SU-2016:0605-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 967521
CVE References: CVE-2015-7575
Sources used:
openSUSE Leap 42.1 (src):    bouncycastle-1.54-19.1
openSUSE 13.2 (src):    bouncycastle-1.54-13.6.1