ECCurve Processing Vulnerability in Bouncy Castle Java and C# Libraries
CVE-2024-29857
7.5HIGH
What is CVE-2024-29857?
A vulnerability exists in the ECCurve.java and ECCurve.cs components of the Bouncy Castle libraries that can lead to excessive CPU usage when processing EC certificates with specially crafted F2m parameters. This issue impacts versions prior to 1.78 for Bouncy Castle Java and before 2.3.1 for Bouncy Castle C#. Users utilizing these libraries may experience performance degradation as a result of this vulnerability, which is crucial for encryption and security functions in various applications.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
