The ASN.1 parser in Bouncy Castle Crypto (aka BC Java) 1.63 can trigger a large attempted memory allocation, and resultant OutOfMemoryError error, via crafted ASN.1 data. This is fixed in 1.64.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2019-10-08 14:15
Updated : 2021-01-20 15:15
NVD link : CVE-2019-17359
Mitre link : CVE-2019-17359
JSON object : View
Products Affected
bouncycastle
- legion-of-the-bouncy-castle-java-crytography-api
CWE
CWE-770
Allocation of Resources Without Limits or Throttling
