Back

MEDIUM

Bouncy Castle BKS-V1 keystore files vulnerable to trivial hash collisions

Published Apr 16, 2018

Description

The default BKS keystore use an HMAC that is only 16 bits long, which can allow an attacker to compromise the integrity of a BKS keystore. Bouncy Castle release 1.47 changes the BKS format to a format which uses a 160 bit HMAC instead. This applies to any BKS keystore generated prior to BC 1.47. For situations where people need to create the files for legacy reasons a specific keystore type "BKS-V1" was introduced in 1.49. It should be noted that the use of "BKS-V1" is discouraged by the library authors and should only be used where it is otherwise safe to do so, as in where the use of a 16 bit checksum for the file integrity check is not going to cause a security issue in itself.

Affected products

Remediation

Red Hat statement

Red Hat Product Security has rated this issue as having a security impact of Low. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.

Metrics

References (11)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner certcc
Published Apr 16, 2018
Updated Sep 16, 2024
Reserved Jan 12, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Mar 30, 2012
GHSA-8477-3V39-GGPM