Bug 1088257 - (CVE-2018-5382) VUL-1: CVE-2018-5382: bouncycastle: BKS-V1 keystore files vulnerable to trivial hash collisions
VUL-1: CVE-2018-5382: bouncycastle: BKS-V1 keystore files vulnerable to trivi...
Classification: openSUSE
Product: openSUSE Distribution
Classification: openSUSE
Component: Security
Leap 15.0
Other Other
: P5 - None : Normal (vote)
: ---
Assigned To: Pedro Monreal Gonzalez
Security Team bot
Depends on:
  Show dependency treegraph
Reported: 2018-04-05 08:42 UTC by Karol Babioch
Modified: 2019-05-29 08:36 UTC (History)
0 users

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Note You need to log in before you can comment on or make changes to this bug.
Description Karol Babioch 2018-04-05 08:42:58 UTC
Affected versions of the package are vulnerable to Hash Collision due to an error in the BKS version 1 keystore files.

BKS is a keystore format, designed to function similarly to a Sun/Oracle JKS keystore. BKS files can contain public keys, private keys and certificates, and they rely on a password-based encryption to provide confidentiality and integrity protections to the keystore contents.

The first version of a BKS file (aka BKS-V1) contained a design flaw when determining the key size used to protect the keystore data. It used the SHA-1 hash function, which is 160 bits in length. In a RFC7292-compliant cryptographic algorithm, the MAC key size should be the same size as the hash function being used, meaning that the MAC key size should be 160 bits long for BKS files.

However, Bouncy Castle BKS-V1 files uses only 16 bits for the MAC key size. Regardless of the complexity of the password, ghe BKS-V1 file will have merely 65,536 different encryption keys. An attacker may bruteforce this password in a matter of seconds by testing all 65K values.



Comment 1 Karol Babioch 2018-04-05 08:46:49 UTC
We are shipping 1.54 (Leap 42.3) and 1.58 (Factory), so not affected by this.