QID 996041

Date Published: 2023-11-27

QID 996041: Java (Maven) Security Update for org.bouncycastle:bcprov-jdk18on (GHSA-wjxj-5m7g-mg7q)

Bouncy Castle for Java before 1.73 contains a potential Denial of Service (DoS) issue within the Bouncy Castle org.bouncycastle.openssl.PEMParser class. This class parses OpenSSL PEM encoded streams containing X.509 certificates, PKCS8 encoded keys, and PKCS7 objects. Parsing a file that has crafted ASN.1 data through the PEMParser causes an OutOfMemoryError, which can enable a denial of service attack.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Medium - 5.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Refer to Github security advisory GHSA-wjxj-5m7g-mg7q for updates and patch information.
    Vendor References

    CVEs related to QID 996041

    Software Advisories
    Advisory ID Software Component Link
    GHSA-wjxj-5m7g-mg7q org.bouncycastle:bcprov-jdk18on URL Logo github.com/advisories/GHSA-wjxj-5m7g-mg7q