cvedb.io
CVE-2016-1000343
HIGH · CVSS 7.5
EPSS exploitation probability: 0%
Published 2018-06-04T13:29:00.437 · Last modified 2026-06-17T00:38:51.677

Summary

In the Bouncy Castle JCE Provider version 1.55 and earlier the DSA key pair generator generates a weak private key if used with default values. If the JCA key pair generator is not explicitly initialised with DSA parameters, 1.55 and earlier generates a private value assuming a 1024 bit key size. In earlier releases this can be dealt with by explicitly passing parameters to the key pair generator.

Affected products

bouncycastle — bc-java

Does this affect you?

Add your gear to cvedb and we'll alert you only when bouncycastle ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.