CVE-2019-17359

HIGH

Bouncycastle Bc-java < 3.0.2.1 - Resource Allocation Without Limits

Title source: rule
STIX 2.1

Description

The ASN.1 parser in Bouncy Castle Crypto (aka BC Java) 1.63 can trigger a large attempted memory allocation, and resultant OutOfMemoryError error, via crafted ASN.1 data. This is fixed in 1.64.

References (16)

Core 16
Core References
Patch, Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpuapr2020.html
Release Notes, Vendor Advisory x_refsource_misc
https://www.bouncycastle.org/releasenotes.html
Patch, Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpujul2020.html
Patch, Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpujan2020.html
Release Notes, Vendor Advisory x_refsource_misc
https://www.bouncycastle.org/latest_releases.html
Third Party Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20191024-0006/
Patch, Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpuoct2020.html
Patch, Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpujan2021.html

Scores

CVSS v3 7.5
EPSS 0.0333
EPSS Percentile 87.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-770
Status published
Products (34)
apache/tomee 7.0.7
apache/tomee 7.1.2
apache/tomee 8.0.1
bouncycastle/bc-java 1.63
netapp/active_iq_unified_manager 7.3 (2 CPE variants)
netapp/active_iq_unified_manager 9.5
netapp/oncommand_api_services
netapp/oncommand_workflow_automation
netapp/service_level_manager
oracle/business_process_management_suite 12.2.1.3.0
... and 24 more
Published Oct 08, 2019
Tracked Since Feb 18, 2026