CVE-2019-17359

The ASN.1 parser in Bouncy Castle Crypto (aka BC Java) 1.63 can trigger a large attempted memory allocation, and resultant OutOfMemoryError error, via crafted ASN.1 data. This is fixed in 1.64.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 91%
VendorProductVersion
bouncycastlebc-java
1.63
apachetomee
7.0.7
apachetomee
7.1.2
apachetomee
8.0.1
netappactive_iq_unified_manager
7.3 ≤
netappactive_iq_unified_manager
7.3 ≤
netappactive_iq_unified_manager
9.5 ≤
netapponcommand_api_services
-
netapponcommand_workflow_automation
-
netappservice_level_manager
-
oraclebusiness_process_management_suite
12.2.1.3.0
oraclebusiness_process_management_suite
12.2.1.4.0
oraclecommunications_convergence
3.0.1.0 ≤
𝑥
≤ 3.0.2.1
oraclecommunications_diameter_signaling_router
8.0.0 ≤
𝑥
≤ 8.2.2
oraclecommunications_session_route_manager
8.2.0 ≤
𝑥
≤ 8.2.2
oracledata_integrator
12.2.1.4.0
oraclefinancial_services_analytical_applications_infrastructure
8.0.6 ≤
𝑥
≤ 8.0.9
oracleflexcube_private_banking
12.0.0
oracleflexcube_private_banking
12.1.0
oraclehospitality_guest_access
4.2.0
oraclemanaged_file_transfer
12.2.1.3.0
oraclemanaged_file_transfer
12.2.1.4.0
oraclepeoplesoft_enterprise_hcm_global_payroll_switzerland
9.2
oraclepeoplesoft_enterprise_peopletools
8.56
oraclepeoplesoft_enterprise_peopletools
8.57
oraclepeoplesoft_enterprise_peopletools
8.58
oracleretail_xstore_point_of_service
18.0.1
oraclesoa_suite
12.2.1.3.0
oraclesoa_suite
12.2.1.4.0
oraclewebcenter_portal
11.1.1.9.0
oraclewebcenter_portal
12.2.1.3.0
oraclewebcenter_portal
12.2.1.4.0
oracleweblogic_server
12.2.1.3.0
oracleweblogic_server
12.2.1.4.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
bouncycastle
bullseye
1.68-2
fixed
bookworm
1.72-2
fixed
sid
1.77-1
fixed
trixie
1.77-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
bouncycastle
disco
not-affected
bionic
not-affected
xenial
not-affected
trusty
dne
References