CVE-2016-2427 (CNNVD-201604-086)
中文标题:
Android Bouncy Castle Crypto APIs for Java 信息泄露漏洞
英文标题:
The AES-GCM specification in RFC 5084, as used in Android 5.x and 6.x, recommends 12 octets for the ...
漏洞描述
中文描述:
Android是美国谷歌(Google)公司和开放手持设备联盟(简称OHA)共同开发的一套以Linux为基础的开源操作系统。Bouncy Castle Crypto APIs for Java是一个用于Java平台且开源的轻量级密码包。 Android的Bouncy Castle Crypto APIs for Java中的asn1/cms/GCMParameters.java文件存在信息泄露漏洞,该漏洞源于程序使用不正确的AES-GCM-ICVlen值。攻击者可借助特制的应用程序利用该漏洞破坏机密保护机制,泄露身份验证密钥。以下版本受到影响:Android 5.0.2之前版本,5.1.1之前版本,6.0之前版本和6.0.1之前版本,Bouncy Castle Crypto APIs for Java 1.54。
英文描述:
The AES-GCM specification in RFC 5084, as used in Android 5.x and 6.x, recommends 12 octets for the aes-ICVlen parameter field, which might make it easier for attackers to defeat a cryptographic protection mechanism and discover an authentication key via a crafted application, aka internal bug 26234568. NOTE: The vendor disputes the existence of this potential issue in Android, stating "This CVE was raised in error: it referred to the authentication tag size in GCM, whose default according to ASN.1 encoding (12 bytes) can lead to vulnerabilities. After careful consideration, it was decided that the insecure default value of 12 bytes was a default only for the encoding and not default anywhere else in Android, and hence no vulnerability existed.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| bouncycastle | bc-java | 1.54 | - | - |
cpe:2.3:a:bouncycastle:bc-java:1.54:*:*:*:*:*:*:*
|
| android | 5.0 | - | - |
cpe:2.3:o:google:android:5.0:*:*:*:*:*:*:*
|
|
| android | 5.0.1 | - | - |
cpe:2.3:o:google:android:5.0.1:*:*:*:*:*:*:*
|
|
| android | 5.1 | - | - |
cpe:2.3:o:google:android:5.1:*:*:*:*:*:*:*
|
|
| android | 5.1.0 | - | - |
cpe:2.3:o:google:android:5.1.0:*:*:*:*:*:*:*
|
|
| android | 6.0 | - | - |
cpe:2.3:o:google:android:6.0:*:*:*:*:*:*:*
|
|
| android | 6.0.1 | - | - |
cpe:2.3:o:google:android:6.0.1:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
参考链接
cve.org
CVSS评分详情
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2016-2427 |
2025-11-11 15:19:06 | 2025-11-11 07:34:16 |
| NVD | nvd_CVE-2016-2427 |
2025-11-11 14:55:06 | 2025-11-11 07:42:57 |
| CNNVD | cnnvd_CNNVD-201604-086 |
2025-11-11 15:09:39 | 2025-11-11 07:52:26 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 信息泄露
- cnnvd_id: 未提取 -> CNNVD-201604-086
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- cvss_score: 未提取 -> 5.5
- cvss_vector: NOT_EXTRACTED -> CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
- cvss_version: NOT_EXTRACTED -> 3.0
- affected_products_count: 0 -> 7
- data_sources: ['cve'] -> ['cve', 'nvd']