CVE-2016-1000343: Bouncycastle Bc-Java
High severity, CVSS 7.5. EPSS: 3.2% chance of exploitation in the next 30 days.
In the Bouncy Castle JCE Provider version 1.55 and earlier the DSA key pair generator generates a weak private key if used with default values. If the JCA key pair generator is not explicitly initialised with DSA parameters, 1.55 and earlier generates a private value assuming a 1024 bit key size. In earlier releases this can be dealt with by explicitly passing parameters to the key pair generator.
Affected products
- Bouncycastle Bc-Java: up to and including 1.55
- Debian Debian Linux: version 8.0 only
Published 2018-06-04. Last modified 2026-06-17.