Bugzilla – Bug 1095850 |
VUL-0: CVE-2016-1000342: bouncycastle: In the Bouncy Castle JCE Provider version 1.55 and earlier ECDSA does not fullyvalidate ASN.1 encoding of signature on verification. It is possible to injectextra elements in the sequence making up the signature a |
Last modified: 2020-04-23 15:25:53 UTC |