CVE-2024-29857

EUVD-2024-1533
An issue was discovered in ECCurve.java and ECCurve.cs in Bouncy Castle Java (BC Java) before 1.78, BC Java LTS before 2.73.6, BC-FJA before 1.0.2.5, and BC C# .Net before 2.3.1. Importing an EC certificate with crafted F2m parameters can lead to excessive CPU consumption during the evaluation of the curve parameters.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 61%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
bouncycastlebc-java
𝑥
≤ 1.77
ADP
bouncycastlebc-fja
𝑥
≤ 1.0.2.4
ADP
bouncycastlebc_c_.net
𝑥
≤ 2.3.0
ADP
Debian logo
Debian Releases
Debian Product
Codename
bouncycastle
bookworm
no-dsa
bullseye
no-dsa
buster
postponed
forky
1.80-3
fixed
sid
1.80-3
fixed
trixie
1.80-3
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
bouncycastle
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
mantic
ignored
noble
needs-triage
oracular
ignored
plucky
needs-triage
questing
needs-triage
xenial
needs-triage
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
bouncycastle
Amazon Linux 2023
0:1.70-4.amzn2023.0.5
fixed
bouncycastle-javadoc
Amazon Linux 2023
0:1.70-4.amzn2023.0.5
fixed
bouncycastle-mail
Amazon Linux 2023
0:1.70-4.amzn2023.0.5
fixed
bouncycastle-pg
Amazon Linux 2023
0:1.70-4.amzn2023.0.5
fixed
bouncycastle-pkix
Amazon Linux 2023
0:1.70-4.amzn2023.0.5
fixed
bouncycastle-tls
Amazon Linux 2023
0:1.70-4.amzn2023.0.5
fixed
bouncycastle-util
Amazon Linux 2023
0:1.70-4.amzn2023.0.5
fixed