{"id":"openSUSE-SU-2020:0607-1","summary":"Security update for bouncycastle","details":"This update for bouncycastle fixes the following issues:\n\nVersion update to 1.60:\n\n* CVE-2018-1000613: Use of Externally-ControlledInput to Select Classes or Code (boo#1100694)\n\n* Release notes:\n    http://www.bouncycastle.org/releasenotes.html\n\nVersion update to 1.59: \n\n* CVE-2017-13098: Fix against Bleichenbacher oracle when not\n  using the lightweight APIs (boo#1072697).\n* Release notes:\n  http://www.bouncycastle.org/releasenotes.html\n\n","modified":"2026-02-04T02:49:08.361110Z","published":"2020-05-03T16:19:33Z","related":["CVE-2017-13098","CVE-2018-1000613"],"upstream":["CVE-2017-13098","CVE-2018-1000613"],"references":[{"type":"ADVISORY","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/SJ5CQDJZHIR5UUASDLGQDV3YILWDOSU3/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1072697"},{"type":"REPORT","url":"https://bugzilla.suse.com/1100694"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-13098"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-1000613"}],"affected":[{"package":{"name":"bouncycastle","ecosystem":"openSUSE:Leap 15.1","purl":"pkg:rpm/opensuse/bouncycastle&distro=openSUSE%20Leap%2015.1"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.60-lp151.3.3.1"}]}],"ecosystem_specific":{"binaries":[{"bouncycastle-javadoc":"1.60-lp151.3.3.1","bouncycastle":"1.60-lp151.3.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2020:0607-1.json"}}],"schema_version":"1.7.3"}