Total vulnerabilities in the database
In the Bouncy Castle JCE Provider version 1.55 and earlier the DSA key pair generator generates a weak private key if used with default values. If the JCA key pair generator is not explicitly initialised with DSA parameters, 1.55 and earlier generates a private value assuming a 1024 bit key size. In earlier releases this can be dealt with by explicitly passing parameters to the key pair generator.
Software | From | Fixed in |
---|---|---|
debian / debian_linux | 8.0 | 8.0.x |
![]() |
- | 1.56 |
![]() |
- | 1.56 |
bouncycastle / bc-java | - | 1.55.x |