CVE-2024-29857

An issue was discovered in ECCurve.java and ECCurve.cs in Bouncy Castle Java (BC Java) before 1.78, BC Java LTS before 2.73.6, BC-FJA before 1.0.2.5, and BC C# .Net before 2.3.1. Importing an EC certificate with crafted F2m parameters can lead to excessive CPU consumption during the evaluation of the curve parameters.
Configurations

No configuration.

History

06 Dec 2024, 14:15

Type Values Removed Values Added
References
  • () https://security.netapp.com/advisory/ntap-20241206-0008/ -

21 Nov 2024, 09:08

Type Values Removed Values Added
References () https://github.com/bcgit/bc-csharp/wiki/CVE%E2%80%902024%E2%80%9029857 - () https://github.com/bcgit/bc-csharp/wiki/CVE%E2%80%902024%E2%80%9029857 -
References () https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902024%E2%80%9029857 - () https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902024%E2%80%9029857 -
References () https://www.bouncycastle.org/latest_releases.html - () https://www.bouncycastle.org/latest_releases.html -

15 Aug 2024, 19:35

Type Values Removed Values Added
CWE CWE-125
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

14 May 2024, 16:13

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-14 15:17

Updated : 2024-12-06 14:15


NVD link : CVE-2024-29857

Mitre link : CVE-2024-29857

CVE.ORG link : CVE-2024-29857


JSON object : View

Products Affected

No product.

CWE
CWE-125

Out-of-bounds Read