cbcvebase.
CVE-2019-17359
published 2019-10-08

CVE-2019-17359: The ASN.1 parser in Bouncy Castle Crypto (aka BC Java) 1.63 can trigger a large attempted memory allocation, and resultant OutOfMemoryError error, via crafted…

high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
The ASN.1 parser in Bouncy Castle Crypto (aka BC Java) 1.63 can trigger a large attempted memory allocation, and resultant OutOfMemoryError error, via crafted ASN.1 data. This is fixed in 1.64.

Affected

31 ranges· showing 25
VendorProductVersion rangeFixed in
apachetomee
apachetomee
apachetomee
bouncycastlebc-java
debianbouncycastle
netappactive_iq_unified_manager>= 7.3
netappactive_iq_unified_manager>= 9.5
oraclebusiness_process_management_suite
oraclebusiness_process_management_suite
oraclecommunications_convergence3.0.1.0 – 3.0.2.1
oraclecommunications_diameter_signaling_router8.0.0 – 8.2.2
oraclecommunications_session_route_manager8.2.0 – 8.2.2
oracledata_integrator
oraclefinancial_services_analytical_applications_infrastructure8.0.6 – 8.0.9
oracleflexcube_private_banking
oracleflexcube_private_banking
oraclehospitality_guest_access
oraclemanaged_file_transfer
oraclemanaged_file_transfer
oraclepeoplesoft_enterprise_hcm_global_payroll_switzerland
oraclepeoplesoft_enterprise_peopletools
oraclepeoplesoft_enterprise_peopletools
oraclepeoplesoft_enterprise_peopletools
oracleretail_xstore_point_of_service
oraclesoa_suite