Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-33202

Опубликовано: 23 нояб. 2023
Источник: redhat
CVSS3: 5.5

Описание

Bouncy Castle for Java before 1.73 contains a potential Denial of Service (DoS) issue within the Bouncy Castle org.bouncycastle.openssl.PEMParser class. This class parses OpenSSL PEM encoded streams containing X.509 certificates, PKCS8 encoded keys, and PKCS7 objects. Parsing a file that has crafted ASN.1 data through the PEMParser causes an OutOfMemoryError, which can enable a denial of service attack. (For users of the FIPS Java API: BC-FJA 1.0.2.3 and earlier are affected; BC-FJA 1.0.2.4 is fixed.)

A flaw was found in Bouncy Castle for the Java pkix module, which is vulnerable to a potential Denial of Service (DoS) issue within the org.bouncycastle.openssl.PEMParser class. This class parses OpenSSL PEM encoded streams containing X.509 certificates, PKCS8 encoded keys, and PKCS7 objects. Parsing a file that has crafted ASN.1 data through the PEMParser causes an OutOfMemoryError, which can enable a denial of service attack.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
A-MQ Clients 2bcpkixNot affected
Logging Subsystem for Red Hat OpenShiftbcpkixNot affected
Migration Toolkit for Applications 6bcpkixNot affected
Migration Toolkit for RuntimesbcpkixNot affected
OpenShift Developer Tools and ServicesjenkinsUnder investigation
OpenShift Developer Tools and Servicesjenkins-2-pluginsUnder investigation
OpenShift ServerlessbcpkixNot affected
Red Hat AMQ Broker 7bcpkixAffected
Red Hat build of Apache Camel for Spring Boot 3bcpkixNot affected
Red Hat build of Apicurio Registry 2bcpkixWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=2251281bc-java: Out of memory while parsing ASN.1 crafted data in org.bouncycastle.openssl.PEMParser class

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 2 лет назад

Bouncy Castle for Java before 1.73 contains a potential Denial of Service (DoS) issue within the Bouncy Castle org.bouncycastle.openssl.PEMParser class. This class parses OpenSSL PEM encoded streams containing X.509 certificates, PKCS8 encoded keys, and PKCS7 objects. Parsing a file that has crafted ASN.1 data through the PEMParser causes an OutOfMemoryError, which can enable a denial of service attack. (For users of the FIPS Java API: BC-FJA 1.0.2.3 and earlier are affected; BC-FJA 1.0.2.4 is fixed.)

CVSS3: 5.5
nvd
около 2 лет назад

Bouncy Castle for Java before 1.73 contains a potential Denial of Service (DoS) issue within the Bouncy Castle org.bouncycastle.openssl.PEMParser class. This class parses OpenSSL PEM encoded streams containing X.509 certificates, PKCS8 encoded keys, and PKCS7 objects. Parsing a file that has crafted ASN.1 data through the PEMParser causes an OutOfMemoryError, which can enable a denial of service attack. (For users of the FIPS Java API: BC-FJA 1.0.2.3 and earlier are affected; BC-FJA 1.0.2.4 is fixed.)

CVSS3: 5.5
debian
около 2 лет назад

Bouncy Castle for Java before 1.73 contains a potential Denial of Serv ...

CVSS3: 5.5
github
около 2 лет назад

Bouncy Castle Denial of Service (DoS)

CVSS3: 3.5
fstec
около 2 лет назад

Уязвимость средства криптографической защиты Bouncy Castle, существующая из-за недостаточной проверки входных данных, позволяющая нарушителю вызвать отказ в обслуживании

5.5 Medium

CVSS3