CVE-2017-13098: high-severity vulnerability in Legion of the Bouncy Castle BouncyCastle TLS
BouncyCastle JCE TLS Bleichenbacher/ROBOT
Published · Updated
Patch soon. It has a working public exploit.
BouncyCastle TLS versions before 1.0.3 have a flaw in how they handle RSA encryption during TLS connections, allowing attackers to potentially recover the private encryption key through repeated connection attempts. This is a serious vulnerability that affects the security of encrypted communications.
BouncyCastle JCE TLS prior to 1.0.3 contains a Bleichenbacher oracle vulnerability (ROBOT attack) when RSA key exchange cipher suites are negotiated. The vulnerability stems from timing or error message differences in RSA decryption handling, enabling an attacker to distinguish valid from invalid ciphertexts and gradually recover the server's private key without authentication.