2009-03-30 03:30:00 2012-11-16 04:52:42

The Legion of the Bouncy Castle Java Cryptography API before release 1.38, as used in Crypto Provider Package before 1.36, has unknown impact and remote attack vectors related to "a Bleichenbacher vulnerability in simple RSA CMS signatures without signed attributes."

Vector

NETWORK

Complexity

LOW

Authentication

NONE

Confidentiality

COMPLETE

Integrity

COMPLETE

Availability

COMPLETE
Autodesk Utility Design Bouncycastle Bouncy-castle-crypto-package 1.29 (not an official CPE) Autodesk VIZ Bouncycastle Bouncy-castle-crypto-package 1.28 (not an official CPE) Autodesk Survey 2006_1 Bouncycastle Bouncy-castle-crypto-package 1.27 (not an official CPE) Bouncycastle Bouncy-castle-crypto-package 1.26 (not an official CPE) Autodesk Utility Design 2005 Bouncycastle Bouncy-castle-crypto-package 1.25 (not an official CPE) Autodesk VIZ 2006 Autodesk Map 3D 2006 Autodesk Material Library 2011 2.0.0.49 Bouncycastle Bouncy-castle-crypto-package 1.01 (not an official CPE) Bouncycastle Bouncy-castle-crypto-package 1.02 (not an official CPE) Automatedqa Testcomplete Demo 7.52.678.3 Automatedqa Testexecute 7.52.678.9 Bouncycastle Bouncy-castle-crypto-package 1.09 (not an official CPE) Autodesk Revit 8 Bouncycastle Bouncy-castle-crypto-package 1.11 (not an official CPE) Autodesk Revit Structure Autodesk Revit Autodesk Revit 7 Bouncycastle Bouncy-castle-crypto-package 1.12 (not an official CPE) Bouncycastle Bouncy-castle-crypto-package 1.13 (not an official CPE) Autodesk Raster Design 2005 Autodesk Material Library Base Resolution Image Library 2012 2.5.0.8 Autodesk Raster Design Autodesk Material Library Base Image Library 2011 2.0.0.49 Autodesk Survey Autodesk Material Library Medium Image Library 2011 2.0.0.49 Autodesk Material Library 2012 2.5.0.8 Autodesk Raster Design 2006 Bouncycastle Bouncy-castle-crypto-package 1.20 (not an official CPE) Bouncycastle Bouncy-castle-crypto-package 1.21 (not an official CPE) Bouncycastle Bouncy-castle-crypto-package 1.22 (not an official CPE) Bouncycastle Bouncy-castle-crypto-package 1.23 (not an official CPE) Bouncycastle Bouncy-castle-crypto-package 1.24 (not an official CPE) Autodesk SketchBook Pro 6.2.6 Bouncycastle Bouncy-castle-crypto-package 1.03 (not an official CPE) Autodesk SketchBook Pro 6.2.5 Bouncycastle Bouncy-castle-crypto-package 1.04 (not an official CPE) Autodesk Survey 2005 Bouncycastle Bouncy-castle-crypto-package 1.05 (not an official CPE) Bouncycastle Bouncy-castle-crypto-package 1.06 (not an official CPE) Bouncycastle Bouncy-castle-crypto-package 1.0 (not an official CPE) Bouncycastle Bouncy-castle-crypto-package 1.07 (not an official CPE) Bouncycastle Bouncy-castle-crypto-package 1.08 (not an official CPE) Autodesk SketchBook Pro 6.2.4 Autodesk SketchBook for Enterprise 2014 6.2.4 Autodesk SketchBook for Enterprise 2014 6.2.5 Autodesk SketchBook Express 6.2.4 Autodesk SketchBook Express 6.2.5 Autodesk SketchBook Copic Edition 6.2.4 Autodesk SketchBook Copic Edition 6.2.5 Automatedqa Testcomplete 7.52.678.3 Bouncycastle Bouncy-castle-crypto-package 1.32 (not an official CPE) Bouncycastle Bouncy-castle-crypto-package 1.33 (not an official CPE) Bouncycastle Bouncy-castle-crypto-package 1.30 (not an official CPE) Bouncycastle Bouncy-castle-crypto-package 1.14 (not an official CPE) Autodesk VRED Professional 2014 Service Release 1 Service Pack 8 Bouncycastle Bouncy-castle-crypto-package 1.15 (not an official CPE) Automatedqa Testcomplete 8.20.538.7 Autodesk Volo View Express 2002.20.0.811 Bouncycastle Bouncy-castle-crypto-package 1.34 (not an official CPE) Bouncycastle Bouncy-castle-crypto-package 1.3.1 (not an official CPE) Autoit 3.3.0.0 Bouncycastle Bouncy-castle-crypto-package 1.35 (not an official CPE) Bouncycastle Bouncy-castle-crypto-package 1.18 (not an official CPE) Bouncycastle Bouncy-castle-crypto-package 1.19 (not an official CPE) Autodesk VRED Professional 2014 Bouncycastle Bouncy-castle-crypto-package 1.16 (not an official CPE) Bouncycastle Bouncy-castle-crypto-package 1.17 (not an official CPE)