Description

An issue was discovered in ECCurve.java and ECCurve.cs in Bouncy Castle Java (BC Java) before 1.78, BC Java LTS before 2.73.6, BC-FJA before 1.0.2.5, and BC C# .Net before 2.3.1. Importing an EC certificate with crafted F2m parameters can lead to excessive CPU consumption during the evaluation of the curve parameters.

INFO

Published Date :

2024-05-09T04:17:29.645Z

Last Modified :

2025-02-13T15:47:48.325Z

Source :

mitre
AFFECTED PRODUCTS

The following products are affected by CVE-2024-29857 vulnerability.

Vendors Products
Bouncycastle
  • Bc-fja
  • Bc-java
  • Bc C .net
Redhat
  • Amq Broker
  • Apache Camel Spring Boot
  • Camel Quarkus
  • Jboss Enterprise Application Platform
  • Quarkus

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact