2024-05-14 16:04:21 +00:00
{
"id" : "CVE-2024-29857" ,
"sourceIdentifier" : "cve@mitre.org" ,
"published" : "2024-05-14T15:17:02.970" ,
2024-12-06 15:03:50 +00:00
"lastModified" : "2024-12-06T14:15:20.263" ,
2024-05-14 18:03:25 +00:00
"vulnStatus" : "Awaiting Analysis" ,
2024-07-14 02:06:08 +00:00
"cveTags" : [ ] ,
2024-05-14 16:04:21 +00:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "An issue was discovered in ECCurve.java and ECCurve.cs in Bouncy Castle Java (BC Java) before 1.78, BC Java LTS before 2.73.6, BC-FJA before 1.0.2.5, and BC C# .Net before 2.3.1. Importing an EC certificate with crafted F2m parameters can lead to excessive CPU consumption during the evaluation of the curve parameters."
2024-05-19 02:03:31 +00:00
} ,
{
"lang" : "es" ,
"value" : "Se descubri\u00f3 un problema en ECCurve.java y ECCurve.cs en Bouncy Castle Java (BC Java) antes de 1.78, BC Java LTS antes de 2.73.6, BC-FJA antes de 1.0.2.5 y BC C# .Net antes de 2.3.1. La importaci\u00f3n de un certificado CE con par\u00e1metros F2m modificados puede provocar un consumo excesivo de CPU durante la evaluaci\u00f3n de los par\u00e1metros de la curva."
2024-05-14 16:04:21 +00:00
}
] ,
2024-08-15 20:03:18 +00:00
"metrics" : {
"cvssMetricV31" : [
{
"source" : "134c704f-9b21-4f2e-91b3-4a467353bcc0" ,
"type" : "Secondary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" ,
2024-12-06 15:03:50 +00:00
"baseScore" : 7.5 ,
"baseSeverity" : "HIGH" ,
2024-08-15 20:03:18 +00:00
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "NONE" ,
"integrityImpact" : "NONE" ,
2024-12-06 15:03:50 +00:00
"availabilityImpact" : "HIGH"
2024-08-15 20:03:18 +00:00
} ,
"exploitabilityScore" : 3.9 ,
"impactScore" : 3.6
}
]
} ,
"weaknesses" : [
{
"source" : "134c704f-9b21-4f2e-91b3-4a467353bcc0" ,
"type" : "Secondary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-125"
}
]
}
] ,
2024-05-14 16:04:21 +00:00
"references" : [
{
"url" : "https://github.com/bcgit/bc-csharp/wiki/CVE%E2%80%902024%E2%80%9029857" ,
"source" : "cve@mitre.org"
} ,
{
"url" : "https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902024%E2%80%9029857" ,
"source" : "cve@mitre.org"
} ,
{
"url" : "https://www.bouncycastle.org/latest_releases.html" ,
"source" : "cve@mitre.org"
2024-12-06 15:03:50 +00:00
} ,
{
"url" : "https://github.com/bcgit/bc-csharp/wiki/CVE%E2%80%902024%E2%80%9029857" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902024%E2%80%9029857" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "https://security.netapp.com/advisory/ntap-20241206-0008/" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "https://www.bouncycastle.org/latest_releases.html" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
2024-05-14 16:04:21 +00:00
}
]
}