ZeroHour

CVE-2019-17359

CVSS 3.1
7.5 high
EPSS
9%p95
Published
()
Modified
Description

The ASN.1 parser in Bouncy Castle Crypto (aka BC Java) 1.63 can trigger a large attempted memory allocation, and resultant OutOfMemoryError error, via crafted ASN.1 data. This is fixed in 1.64.

Vendors
bouncycastleapachenetapporacle
Products
bc-java, tomee, active iq unified manager, oncommand api services, oncommand workflow automation, service level manager, business process management suite, communications convergence, communications diameter signaling router, communications session route manager, data integrator, financial services analytical applications infrastructure
Weakness
CWE-770
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.