CVE-2024-29857

An issue was discovered in ECCurve.java and ECCurve.cs in Bouncy Castle Java (BC Java) before 1.78, BC Java LTS before 2.73.6, BC-FJA before 1.0.2.5, and BC C# .Net before 2.3.1. Importing an EC certificate with crafted F2m parameters can lead to excessive CPU consumption during the evaluation of the curve parameters.
Configurations

No configuration.

History

21 Nov 2024, 09:08

Type Values Removed Values Added
References () https://github.com/bcgit/bc-csharp/wiki/CVE%E2%80%902024%E2%80%9029857 - () https://github.com/bcgit/bc-csharp/wiki/CVE%E2%80%902024%E2%80%9029857 -
References () https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902024%E2%80%9029857 - () https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902024%E2%80%9029857 -
References () https://www.bouncycastle.org/latest_releases.html - () https://www.bouncycastle.org/latest_releases.html -

15 Aug 2024, 19:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CWE CWE-125
Summary
  • (es) Se descubrió un problema en ECCurve.java y ECCurve.cs en Bouncy Castle Java (BC Java) antes de 1.78, BC Java LTS antes de 2.73.6, BC-FJA antes de 1.0.2.5 y BC C# .Net antes de 2.3.1. La importación de un certificado CE con parámetros F2m modificados puede provocar un consumo excesivo de CPU durante la evaluación de los parámetros de la curva.

14 May 2024, 15:17

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-14 15:17

Updated : 2024-11-21 09:08


NVD link : CVE-2024-29857

Mitre link : CVE-2024-29857

CVE.ORG link : CVE-2024-29857


JSON object : View

Products Affected

No product.

CWE
CWE-125

Out-of-bounds Read