NA

CVE-2024-29857

Published: 14/05/2024 Updated: 14/05/2024

Vulnerability Summary

An issue exists in ECCurve.java and ECCurve.cs in Bouncy Castle Java (BC Java) prior to 1.78, BC Java LTS prior to 2.73.6, BC-FJA prior to 1.0.2.5, and BC C# .Net prior to 2.3.1. Importing an EC certificate with crafted F2m parameters can lead to excessive CPU consumption during the evaluation of the curve parameters.

Vendor Advisories

Debian Bug report logs - #1070655 bouncycastle: CVE-2024-29857 CVE-2024-30171 CVE-2024-30172 CVE-2024-34447 Package: src:bouncycastle; Maintainer for src:bouncycastle is Debian Java Maintainers <pkg-java-maintainers@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Mon, 6 May 2024 ...