Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-9340

Опубликовано: 22 авг. 2025
Источник: redhat
CVSS3: 5.9

Описание

Out-of-bounds Write vulnerability in Legion of the Bouncy Castle Inc. Bouncy Castle for Java bc-fips on All (API modules). This vulnerability is associated with program files org/bouncycastle/jcajce/provider/BaseCipher. This issue affects Bouncy Castle for Java: from BC-FJA 2.1.0 through 2.1.0.

A flaw was found in Bouncy Castle for Java bc-fips. This out-of-bounds write vulnerability, located in the org/bouncycastle/jcajce/provider/BaseCipher program files, could allow a local attacker to cause information disclosure, data modification, or a denial of service without requiring any privileges or user interaction.

Отчет

This vulnerability is rated Moderate. However, Red Hat products are not affected by this vulnerability as the vulnerable code is not present in the shipped components.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss Enterprise Application Platform 8bc-fipsNot affected
Red Hat JBoss Enterprise Application Platform Expansion Packbc-fipsNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2390279org.bouncycastle/bc-fips: Bouncy Castle for Java bc-fips: Out-of-bounds Write vulnerability allows local information disclosure, data modification, or denial of service.

5.9 Medium

CVSS3

Связанные уязвимости

nvd
7 месяцев назад

Out-of-bounds Write vulnerability in Legion of the Bouncy Castle Inc. Bouncy Castle for Java bc-fips on All (API modules). This vulnerability is associated with program files org/bouncycastle/jcajce/provider/BaseCipher. This issue affects Bouncy Castle for Java: from BC-FJA 2.1.0 through 2.1.0.

github
7 месяцев назад

Bouncy Castle for Java has Out-of-Bounds Write Vulnerability

5.9 Medium

CVSS3