THREATINT

We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Zendesk (Helpdesk and Chat)

Ok

PUBLISHED

CVE-2024-29857

Updated:2024-05-13

Description

An issue was discovered in ECCurve.java and ECCurve.cs in Bouncy Castle Java (BC Java) before 1.78, BC Java LTS before 2.73.6, BC-FJA before 1.0.2.5, and BC C# .Net before 2.3.1. Importing an EC certificate with crafted F2m parameters can lead to excessive CPU consumption during the evaluation of the curve parameters.

References

https://www.bouncycastle.org/latest_releases.html

https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902024%E2%80%9029857

https://github.com/bcgit/bc-csharp/wiki/CVE%E2%80%902024%E2%80%9029857

cve.org CVE-2024-29857

nvd.nist.gov CVE-2024-29857

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2024-29857