Asymmetric denial of service In org.bouncycastle:bcprov-jdk15on
Description
Bouncy Castle Denial of Service (DoS) Bouncy Castle for Java before 1.73 contains a potential Denial of Service (DoS) issue within the Bouncy Castle org.bouncycastle.openssl.PEMParser class. This class parses OpenSSL PEM encoded streams containing X.509 certificates, PKCS8 encoded keys, and PKCS7 objects. Parsing a file that has crafted ASN.1 data through the PEMParser causes an OutOfMemoryError, which can enable a denial of service attack.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
debian 11 | - | ||
maven | 1.73 | ||
maven | 1.70 | ||
maven | 1.73 | ||
maven | 1.73 | ||
maven | 1.73 | ||
maven | 1.73 | ||
maven | 1.73 | ||
maven | 1.73 | ||
maven | 1.73 |
1-10 of 16
10
Aliases
1. 2. 3. 4. 5. 6. 7.
References
1. 2. 3. 4.