CVE-2019-17359
published 2019-10-08CVE-2019-17359: The ASN.1 parser in Bouncy Castle Crypto (aka BC Java) 1.63 can trigger a large attempted memory allocation, and resultant OutOfMemoryError error, via crafted…
PriorityP343high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
8.95%
94.7th percentile
The ASN.1 parser in Bouncy Castle Crypto (aka BC Java) 1.63 can trigger a large attempted memory allocation, and resultant OutOfMemoryError error, via crafted ASN.1 data. This is fixed in 1.64.
Affected
31 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tomee | — | — |
| apache | tomee | — | — |
| apache | tomee | — | — |
| bouncycastle | bc-java | — | — |
| debian | bouncycastle | — | — |
| netapp | active_iq_unified_manager | >= 7.3 | — |
| netapp | active_iq_unified_manager | >= 9.5 | — |
| oracle | business_process_management_suite | — | — |
| oracle | business_process_management_suite | — | — |
| oracle | communications_convergence | 3.0.1.0 – 3.0.2.1 | — |
| oracle | communications_diameter_signaling_router | 8.0.0 – 8.2.2 | — |
| oracle | communications_session_route_manager | 8.2.0 – 8.2.2 | — |
| oracle | data_integrator | — | — |
| oracle | financial_services_analytical_applications_infrastructure | 8.0.6 – 8.0.9 | — |
| oracle | flexcube_private_banking | — | — |
| oracle | flexcube_private_banking | — | — |
| oracle | hospitality_guest_access | — | — |
| oracle | managed_file_transfer | — | — |
| oracle | managed_file_transfer | — | — |
| oracle | peoplesoft_enterprise_hcm_global_payroll_switzerland | — | — |
| oracle | peoplesoft_enterprise_peopletools | — | — |
| oracle | peoplesoft_enterprise_peopletools | — | — |
| oracle | peoplesoft_enterprise_peopletools | — | — |
| oracle | retail_xstore_point_of_service | — | — |
| oracle | soa_suite | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_debian7.5LOW
vendor_oracle7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Runtime Java agent for ODI (Bouncy Castle Java Library) — CVE-2019-17359
vendor_oracle·2021-01-15·CVSS 7.5
CVE-2019-17359 [HIGH] Oracle Oracle Fusion Middleware Risk Matrix: Runtime Java agent for ODI (Bouncy Castle Java Library) — CVE-2019-17359
Oracle Oracle Fusion Middleware Risk Matrix: Runtime Java agent for ODI (Bouncy Castle Java Library) vulnerability
CVE: CVE-2019-17359
CVSS: 7.5
Protocol: HTTPS
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2021 (JAN 2021)
Oracle
Oracle Oracle Communications Risk Matrix: IDIH (Bouncy Castle Java Library) — CVE-2019-17359
vendor_oracle·2020-10-15·CVSS 7.5
CVE-2019-17359 [HIGH] Oracle Oracle Communications Risk Matrix: IDIH (Bouncy Castle Java Library) — CVE-2019-17359
Oracle Oracle Communications Risk Matrix: IDIH (Bouncy Castle Java Library) vulnerability
CVE: CVE-2019-17359
CVSS: 7.5
Protocol: HTTPS
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2020 (OCT 2020)
Oracle
Oracle Oracle Communications Applications Risk Matrix: S/MIME Configuration (Bouncy Castle Java Library) — CVE-2019-17359
vendor_oracle·2020-07-15·CVSS 7.5
CVE-2019-17359 [HIGH] Oracle Oracle Communications Applications Risk Matrix: S/MIME Configuration (Bouncy Castle Java Library) — CVE-2019-17359
Oracle Oracle Communications Applications Risk Matrix: S/MIME Configuration (Bouncy Castle Java Library) vulnerability
CVE: CVE-2019-17359
CVSS: 7.5
Protocol: HTTPS
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2020 (JUL 2020)
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: Infrastructure (Bouncy Castle Java Library) — CVE-2019-17359
vendor_oracle·2020-04-15·CVSS 7.5
CVE-2019-17359 [HIGH] Oracle Oracle Financial Services Applications Risk Matrix: Infrastructure (Bouncy Castle Java Library) — CVE-2019-17359
Oracle Oracle Financial Services Applications Risk Matrix: Infrastructure (Bouncy Castle Java Library) vulnerability
CVE: CVE-2019-17359
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2020 (APR 2020)
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Third Party Tools (Bouncy Castle Java Library) — CVE-2019-17359
vendor_oracle·2020-01-15·CVSS 7.5
CVE-2019-17359 [HIGH] Oracle Oracle Fusion Middleware Risk Matrix: Third Party Tools (Bouncy Castle Java Library) — CVE-2019-17359
Oracle Oracle Fusion Middleware Risk Matrix: Third Party Tools (Bouncy Castle Java Library) vulnerability
CVE: CVE-2019-17359
CVSS: 7.5
Protocol: HTTPS
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2020 (JAN 2020)
Debian
CVE-2019-17359: bouncycastle - The ASN.1 parser in Bouncy Castle Crypto (aka BC Java) 1.63 can trigger a large ...
vendor_debian·2019·CVSS 7.5
CVE-2019-17359 [HIGH] CVE-2019-17359: bouncycastle - The ASN.1 parser in Bouncy Castle Crypto (aka BC Java) 1.63 can trigger a large ...
The ASN.1 parser in Bouncy Castle Crypto (aka BC Java) 1.63 can trigger a large attempted memory allocation, and resultant OutOfMemoryError error, via crafted ASN.1 data. This is fixed in 1.64.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
GHSA
Out-of-Memory Error in Bouncy Castle Crypto
ghsa·2019-10-17
CVE-2019-17359 [HIGH] CWE-770 Out-of-Memory Error in Bouncy Castle Crypto
Out-of-Memory Error in Bouncy Castle Crypto
The ASN.1 parser in Bouncy Castle Crypto (aka BC Java) 1.63 can trigger a large attempted memory allocation, and resultant OutOfMemoryError error, via crafted ASN.1 data. This is fixed in 1.64.
OSV
Out-of-Memory Error in Bouncy Castle Crypto
osv·2019-10-17
CVE-2019-17359 [HIGH] Out-of-Memory Error in Bouncy Castle Crypto
Out-of-Memory Error in Bouncy Castle Crypto
The ASN.1 parser in Bouncy Castle Crypto (aka BC Java) 1.63 can trigger a large attempted memory allocation, and resultant OutOfMemoryError error, via crafted ASN.1 data. This is fixed in 1.64.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://lists.apache.org/thread.html/r02f887807a49cfd1f1ad53f7a61f3f8e12f60ba2c930bec163031209%40%3Ccommits.tomee.apache.org%3Ehttps://lists.apache.org/thread.html/r16c3a90cb35ae8a9c74fd5c813c16d6ac255709c9f9d71cd409e007d%40%3Ccommits.tomee.apache.org%3Ehttps://lists.apache.org/thread.html/r467ade3fef3493f1fff1a68a256d087874e1f858ad1de7a49fe05d27%40%3Ccommits.tomee.apache.org%3Ehttps://lists.apache.org/thread.html/r4d475dcaf4f57115fa57d8e06c3823ca398b35468429e7946ebaefdc%40%3Ccommits.tomee.apache.org%3Ehttps://lists.apache.org/thread.html/r79b6a6aa0dd1aeb57bd253d94794bc96f1ec005953c4bd5414cc0db0%40%3Ccommits.tomee.apache.org%3Ehttps://lists.apache.org/thread.html/r8ecb5b76347f84b6e3c693f980dbbead88c25f77b815053c4e6f2c30%40%3Ccommits.tomee.apache.org%3Ehttps://lists.apache.org/thread.html/r91b07985b1307390a58c5b9707f0b28ef8e9c9e1c86670459f20d601%40%3Ccommits.tomee.apache.org%3Ehttps://lists.apache.org/thread.html/re60f980c092ada4bfe236dcfef8b6ca3e8f3b150fc0f51b8cc13d59d%40%3Ccommits.tomee.apache.org%3Ehttps://security.netapp.com/advisory/ntap-20191024-0006/https://www.bouncycastle.org/latest_releases.htmlhttps://www.bouncycastle.org/releasenotes.htmlhttps://www.oracle.com/security-alerts/cpuapr2020.htmlhttps://www.oracle.com/security-alerts/cpujan2020.htmlhttps://www.oracle.com/security-alerts/cpujan2021.htmlhttps://www.oracle.com/security-alerts/cpujul2020.htmlhttps://www.oracle.com/security-alerts/cpuoct2020.htmlhttps://lists.apache.org/thread.html/r02f887807a49cfd1f1ad53f7a61f3f8e12f60ba2c930bec163031209%40%3Ccommits.tomee.apache.org%3Ehttps://lists.apache.org/thread.html/r16c3a90cb35ae8a9c74fd5c813c16d6ac255709c9f9d71cd409e007d%40%3Ccommits.tomee.apache.org%3Ehttps://lists.apache.org/thread.html/r467ade3fef3493f1fff1a68a256d087874e1f858ad1de7a49fe05d27%40%3Ccommits.tomee.apache.org%3Ehttps://lists.apache.org/thread.html/r4d475dcaf4f57115fa57d8e06c3823ca398b35468429e7946ebaefdc%40%3Ccommits.tomee.apache.org%3Ehttps://lists.apache.org/thread.html/r79b6a6aa0dd1aeb57bd253d94794bc96f1ec005953c4bd5414cc0db0%40%3Ccommits.tomee.apache.org%3Ehttps://lists.apache.org/thread.html/r8ecb5b76347f84b6e3c693f980dbbead88c25f77b815053c4e6f2c30%40%3Ccommits.tomee.apache.org%3Ehttps://lists.apache.org/thread.html/r91b07985b1307390a58c5b9707f0b28ef8e9c9e1c86670459f20d601%40%3Ccommits.tomee.apache.org%3Ehttps://lists.apache.org/thread.html/re60f980c092ada4bfe236dcfef8b6ca3e8f3b150fc0f51b8cc13d59d%40%3Ccommits.tomee.apache.org%3Ehttps://security.netapp.com/advisory/ntap-20191024-0006/https://www.bouncycastle.org/latest_releases.htmlhttps://www.bouncycastle.org/releasenotes.htmlhttps://www.oracle.com/security-alerts/cpuapr2020.htmlhttps://www.oracle.com/security-alerts/cpujan2020.htmlhttps://www.oracle.com/security-alerts/cpujan2021.htmlhttps://www.oracle.com/security-alerts/cpujul2020.htmlhttps://www.oracle.com/security-alerts/cpuoct2020.html
2019-10-08
Published