An issue was discovered in Bouncy Castle Java TLS API and JSSE Provider before 1.78. Timing-based leakage may occur in RSA based handshakes because of exception processing.
{
"binaries": [
{
"binary_version": "1.51-4ubuntu1",
"binary_name": "libbcmail-java"
},
{
"binary_version": "1.51-4ubuntu1",
"binary_name": "libbcpg-java"
},
{
"binary_version": "1.51-4ubuntu1",
"binary_name": "libbcpkix-java"
},
{
"binary_version": "1.51-4ubuntu1",
"binary_name": "libbcprov-java"
}
]
}{
"binaries": [
{
"binary_version": "1.68-5",
"binary_name": "libbcmail-java"
},
{
"binary_version": "1.68-5",
"binary_name": "libbcpg-java"
},
{
"binary_version": "1.68-5",
"binary_name": "libbcpkix-java"
},
{
"binary_version": "1.68-5",
"binary_name": "libbcprov-java"
},
{
"binary_version": "1.68-5",
"binary_name": "libbctls-java"
}
]
}{
"binaries": [
{
"binary_version": "1.77-1",
"binary_name": "libbcjmail-java"
},
{
"binary_version": "1.77-1",
"binary_name": "libbcmail-java"
},
{
"binary_version": "1.77-1",
"binary_name": "libbcpg-java"
},
{
"binary_version": "1.77-1",
"binary_name": "libbcpkix-java"
},
{
"binary_version": "1.77-1",
"binary_name": "libbcprov-java"
},
{
"binary_version": "1.77-1",
"binary_name": "libbctls-java"
},
{
"binary_version": "1.77-1",
"binary_name": "libbcutil-java"
}
]
}{
"binaries": [
{
"binary_version": "1.77-1",
"binary_name": "libbcjmail-java"
},
{
"binary_version": "1.77-1",
"binary_name": "libbcmail-java"
},
{
"binary_version": "1.77-1",
"binary_name": "libbcpg-java"
},
{
"binary_version": "1.77-1",
"binary_name": "libbcpkix-java"
},
{
"binary_version": "1.77-1",
"binary_name": "libbcprov-java"
},
{
"binary_version": "1.77-1",
"binary_name": "libbctls-java"
},
{
"binary_version": "1.77-1",
"binary_name": "libbcutil-java"
}
]
}{
"binaries": [
{
"binary_version": "1.80-3",
"binary_name": "libbcjmail-java"
},
{
"binary_version": "1.80-3",
"binary_name": "libbcmail-java"
},
{
"binary_version": "1.80-3",
"binary_name": "libbcpg-java"
},
{
"binary_version": "1.80-3",
"binary_name": "libbcpkix-java"
},
{
"binary_version": "1.80-3",
"binary_name": "libbcprov-java"
},
{
"binary_version": "1.80-3",
"binary_name": "libbctls-java"
},
{
"binary_version": "1.80-3",
"binary_name": "libbcutil-java"
}
]
}