ECCurve Processing Vulnerability in Bouncy Castle Java and C# Libraries
CVE-2024-29857

7.5HIGH

Key Information:

Vendor
CVE Published:
14 May 2024

What is CVE-2024-29857?

A vulnerability exists in the ECCurve.java and ECCurve.cs components of the Bouncy Castle libraries that can lead to excessive CPU usage when processing EC certificates with specially crafted F2m parameters. This issue impacts versions prior to 1.78 for Bouncy Castle Java and before 2.3.1 for Bouncy Castle C#. Users utilizing these libraries may experience performance degradation as a result of this vulnerability, which is crucial for encryption and security functions in various applications.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.