CVE-2007-6721
Last modified
CVE-2007-6721 is a vulnerability of currently unknown severity. The Legion of the Bouncy Castle Java Cryptography API before release 1.38, as used in Crypto Provider Package before 1.36, has unknown impact and remote attack vectors related to "a Bleichenbacher vulnerability in simple RSA CMS signatures without signed attributes.". EPSS estimates a 2.41% chance of exploitation in the next 30 days.
Description
The Legion of the Bouncy Castle Java Cryptography API before release 1.38, as used in Crypto Provider Package before 1.36, has unknown impact and remote attack vectors related to "a Bleichenbacher vulnerability in simple RSA CMS signatures without signed attributes."
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Bouncycastle | Bc-Java | <= 1.37 |
| Bouncycastle | Bc-Java | 1.01 |
| Bouncycastle | Bc-Java | 1.02 |
| Bouncycastle | Bc-Java | 1.03 |
| Bouncycastle | Bc-Java | 1.04 |
| Bouncycastle | Bc-Java | 1.05 |
| Bouncycastle | Bc-Java | 1.06 |
| Bouncycastle | Bc-Java | 1.07 |
| Bouncycastle | Bc-Java | 1.08 |
| Bouncycastle | Bc-Java | 1.09 |
| Bouncycastle | Bc-Java | 1.10 |
| Bouncycastle | Bc-Java | 1.11 |
| Bouncycastle | Bc-Java | 1.12 |
| Bouncycastle | Bc-Java | 1.13 |
| Bouncycastle | Bc-Java | 1.14 |
| Bouncycastle | Bc-Java | 1.15 |
| Bouncycastle | Bc-Java | 1.16 |
| Bouncycastle | Bc-Java | 1.17 |
| Bouncycastle | Bc-Java | 1.18 |
| Bouncycastle | Bc-Java | 1.19 |
| Bouncycastle | Bc-Java | 1.20 |
| Bouncycastle | Bc-Java | 1.21 |
| Bouncycastle | Bc-Java | 1.22 |
| Bouncycastle | Bc-Java | 1.23 |
| Bouncycastle | Bc-Java | 1.24 |
| Bouncycastle | Bc-Java | 1.25 |
| Bouncycastle | Bc-Java | 1.26 |
| Bouncycastle | Bc-Java | 1.27 |
| Bouncycastle | Bc-Java | 1.28 |
| Bouncycastle | Bc-Java | 1.29 |
| Bouncycastle | Bc-Java | 1.30 |
| Bouncycastle | Bc-Java | 1.31 |
| Bouncycastle | Bc-Java | 1.32 |
| Bouncycastle | Bc-Java | 1.33 |
| Bouncycastle | Bc-Java | 1.34 |
| Bouncycastle | Bc-Java | 1.35 |
| Bouncycastle | Bc-Java | 1.36 |
| Bouncycastle | Bouncy-Castle-Crypto-Package | <= 1.35 |
| Bouncycastle | Bouncy-Castle-Crypto-Package | 1.0 |
| Bouncycastle | Bouncy-Castle-Crypto-Package | 1.01 |
| Bouncycastle | Bouncy-Castle-Crypto-Package | 1.02 |
| Bouncycastle | Bouncy-Castle-Crypto-Package | 1.03 |
| Bouncycastle | Bouncy-Castle-Crypto-Package | 1.3.1 |
| Bouncycastle | Bouncy-Castle-Crypto-Package | 1.04 |
| Bouncycastle | Bouncy-Castle-Crypto-Package | 1.05 |
| Bouncycastle | Bouncy-Castle-Crypto-Package | 1.06 |
| Bouncycastle | Bouncy-Castle-Crypto-Package | 1.07 |
| Bouncycastle | Bouncy-Castle-Crypto-Package | 1.08 |
| Bouncycastle | Bouncy-Castle-Crypto-Package | 1.09 |
| Bouncycastle | Bouncy-Castle-Crypto-Package | 1.11 |
Showing 50 of 72 affected configurations. See NVD for the full list.
References
- http://www.bouncycastle.org/csharp/Patch, Vendor Advisory
- http://www.bouncycastle.org/devmailarchive/msg08195.htmlPatch, Vendor Advisory
- http://www.bouncycastle.org/csharp/Patch, Vendor Advisory
- http://www.bouncycastle.org/devmailarchive/msg08195.htmlPatch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-6721?
How severe is CVE-2007-6721?
How do I fix CVE-2007-6721?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2007
- CVE-2007-6715Mozilla Firefox allows remote attackers to cause a denial of…
- CVE-2007-6716fs/direct-io.c in the dio subsystem in the Linux kernel befo…5.5
- CVE-2007-6717Buffer overflow in tftp in bos.net.tcp.client in IBM AIX 5.2…
- CVE-2007-6718MPlayer, possibly 1.0rc1, allows remote attackers to cause a…
- CVE-2007-6719SQL injection vulnerability in Wiz-Ad 1.3 allows remote atta…
- CVE-2007-6720libmikmod 3.1.9 through 3.2.0, as used by MikMod, SDL-mixer,…
- CVE-2007-6722Vidalia bundle before 0.1.2.18, when running on Windows and …
- CVE-2007-6723TorK before 0.22, when running on Windows and Mac OS X, inst…
- CVE-2007-6724Vidalia bundle before 0.1.2.18, when running on Windows, ins…
- CVE-2007-6725The CCITTFax decoding filter in Ghostscript 8.60, 8.61, and …
- CVE-2007-6726Multiple cross-site scripting (XSS) vulnerabilities in Dojo …
- CVE-2007-6727SQL injection vulnerability in topic.php in KerviNet Forum 1…
Are you affected by CVE-2007-6721?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
