NA

CVE-2024-30171

Published: 14/05/2024 Updated: 14/05/2024

Vulnerability Summary

An issue exists in Bouncy Castle Java TLS API and JSSE Provider prior to 1.78. Timing-based leakage may occur in RSA based handshakes because of exception processing.

Vendor Advisories

Debian Bug report logs - #1070655 bouncycastle: CVE-2024-29857 CVE-2024-30171 CVE-2024-30172 CVE-2024-34447 Package: src:bouncycastle; Maintainer for src:bouncycastle is Debian Java Maintainers <pkg-java-maintainers@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Mon, 6 May 2024 ...