CVE-2020-8929
Summary
| CVE | CVE-2020-8929 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-10-19 13:15:00 UTC |
| Updated | 2020-10-29 22:16:00 UTC |
| Description | A mis-handling of invalid unicode characters in the Java implementation of Tink versions prior to 1.5 allows an attacker to change the ID part of a ciphertext, which result in the creation of a second ciphertext that can decrypt to the same plaintext. This can be a problem with encrypting deterministic AEAD with a single key, and rely on a unique ciphertext-per-plaintext. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Fixing ciphertext malleability issue in Java caused by storing the ci… · google/tink@93d839a · GitHub | CONFIRM | github.com | Patch, Third Party Advisory |
| Ciphertext Malleability Issue in Tink Java · Advisory · google/tink · GitHub | CONFIRM | github.com | Patch, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Peter Esbensen
Legacy QID Mappings
- 983214 Java (maven) Security Update for com.google.crypto.tink:tink (GHSA-g5vf-v6wf-7w2r)