Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update Bouncy Castle #833

Closed
Neustradamus opened this issue Dec 31, 2020 · 6 comments
Closed

Update Bouncy Castle #833

Neustradamus opened this issue Dec 31, 2020 · 6 comments

Comments

@J-Jamet J-Jamet changed the title Please update Bouncy Castle Update Bouncy Castle Dec 31, 2020
@J-Jamet J-Jamet added enhancement and removed bug labels Dec 31, 2020
@J-Jamet
Copy link
Member

J-Jamet commented Jan 2, 2021

Version 1.68 of org.bouncycastle:bcprov-jdk15on requires JDK 15 which can pose other problems (It's not yet natively on a stable version of Debian).
-> Unsupported class file major version 59

I don't see security issue impacting the app with the current version 1.65.1 of org.bouncycastle:bcprov-jdk15on dated May 2020.
If I'm wrong, please highlight the specific issue concerned.

@Neustradamus
Copy link
Author

There are CVEs solved in 1.67.

@J-Jamet
Copy link
Member

J-Jamet commented Jan 2, 2021

It is not a very precise highlight ...

@Neustradamus
Copy link
Author

@J-Jamet
Copy link
Member

J-Jamet commented Jan 2, 2021

-> https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-28052

I saw this issue but KeePassDX does not use the method OpenBSDBCrypt.checkPassword so the application is not impacted.

@Neustradamus
Copy link
Author

@J-Jamet: Thanks a lot!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants