Описание
An issue was discovered in Bouncy Castle Java Cryptography APIs before 1.78. An Ed25519 verification code infinite loop can occur via a crafted signature and public key.
A flaw was found in the Bouncy Castle Java Cryptography APIs. Affected versions of this package are vulnerable to an Infinite loop issue in ED25519 verification in the ScalarUtil class. This flaw allows an attacker to send a malicious signature and public key to trigger a denial of service.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Cryostat 2 | org.bouncycastle:bcprov-jdk18on | Will not fix | ||
| Cryostat 3 | org.bouncycastle:bcprov-jdk18on | Not affected | ||
| Red Hat build of Apache Camel for Spring Boot 3 | org.bouncycastle:bcprov-jdk18on | Not affected | ||
| Red Hat Build of Keycloak | org.bouncycastle:bcprov-jdk18on | Affected | ||
| Red Hat Data Grid 8 | org.bouncycastle:bcprov-jdk18on | Not affected | ||
| Red Hat Fuse 7 | org.bouncycastle:bcprov-jdk18on | Not affected | ||
| Red Hat JBoss Enterprise Application Platform Expansion Pack | org.bouncycastle:bcprov-jdk18on | Not affected | ||
| streams for Apache Kafka | org.bouncycastle:bcprov-jdk18on | Will not fix | ||
| Important: Red Hat JBoss Enterprise Application Platform 7.4.18 Security update | org.bouncycastle | Fixed | RHSA-2024:5147 | 08.08.2024 |
| Red Hat AMQ Broker 7 | org.bouncycastle | Fixed | RHSA-2024:4271 | 02.07.2024 |
Показывать по
Дополнительная информация
Статус:
7.5 High
CVSS3
Связанные уязвимости
An issue was discovered in Bouncy Castle Java Cryptography APIs before 1.78. An Ed25519 verification code infinite loop can occur via a crafted signature and public key.
An issue was discovered in Bouncy Castle Java Cryptography APIs before 1.78. An Ed25519 verification code infinite loop can occur via a crafted signature and public key.
An issue was discovered in Bouncy Castle Java Cryptography APIs before ...
Bouncy Castle crafted signature and public key can be used to trigger an infinite loop
Уязвимость компонента Cryptography APIs средства криптографической защиты Bouncy Castle, позволяющая нарушителю раскрыть защищаемую информацию
7.5 High
CVSS3