CVE-2023-33202
published 2023-11-23CVE-2023-33202: Bouncy Castle for Java before 1.73 contains a potential Denial of Service (DoS) issue within the Bouncy Castle org.bouncycastle.openssl.PEMParser class. This…
PriorityP420medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
0.93%
57.0th percentile
Bouncy Castle for Java before 1.73 contains a potential Denial of Service (DoS) issue within the Bouncy Castle org.bouncycastle.openssl.PEMParser class. This class parses OpenSSL PEM encoded streams containing X.509 certificates, PKCS8 encoded keys, and PKCS7 objects. Parsing a file that has crafted ASN.1 data through the PEMParser causes an OutOfMemoryError, which can enable a denial of service attack. (For users of the FIPS Java API: BC-FJA 1.0.2.3 and earlier are affected; BC-FJA 1.0.2.4 is fixed.)
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| bouncycastle | bouncy_castle_for_java | < 1.73 | 1.73 |
| bouncycastle | fips_java_api | < 1.0.2.4 | 1.0.2.4 |
| debian | bouncycastle | < bouncycastle 1.77-1 (forky) | bouncycastle 1.77-1 (forky) |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_oracle5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2023-33202: Bouncy Castle for Java before 1
osv·2023-11-23·CVSS 5.5
CVE-2023-33202 [MEDIUM] CVE-2023-33202: Bouncy Castle for Java before 1
Bouncy Castle for Java before 1.73 contains a potential Denial of Service (DoS) issue within the Bouncy Castle org.bouncycastle.openssl.PEMParser class. This class parses OpenSSL PEM encoded streams containing X.509 certificates, PKCS8 encoded keys, and PKCS7 objects. Parsing a file that has crafted ASN.1 data through the PEMParser causes an OutOfMemoryError, which can enable a denial of service attack. (For users of the FIPS Java API: BC-FJA 1.0.2.3 and earlier are affected; BC-FJA 1.0.2.4 is fixed.)
GHSA
Bouncy Castle Denial of Service (DoS)
ghsa·2023-11-23
CVE-2023-33202 [MEDIUM] CWE-400 Bouncy Castle Denial of Service (DoS)
Bouncy Castle Denial of Service (DoS)
Bouncy Castle for Java before 1.73 contains a potential Denial of Service (DoS) issue within the Bouncy Castle org.bouncycastle.openssl.PEMParser class. This class parses OpenSSL PEM encoded streams containing X.509 certificates, PKCS8 encoded keys, and PKCS7 objects. Parsing a file that has crafted ASN.1 data through the PEMParser causes an OutOfMemoryError, which can enable a denial of service attack.
OSV
Bouncy Castle Denial of Service (DoS)
osv·2023-11-23
CVE-2023-33202 [MEDIUM] Bouncy Castle Denial of Service (DoS)
Bouncy Castle Denial of Service (DoS)
Bouncy Castle for Java before 1.73 contains a potential Denial of Service (DoS) issue within the Bouncy Castle org.bouncycastle.openssl.PEMParser class. This class parses OpenSSL PEM encoded streams containing X.509 certificates, PKCS8 encoded keys, and PKCS7 objects. Parsing a file that has crafted ASN.1 data through the PEMParser causes an OutOfMemoryError, which can enable a denial of service attack.
Oracle
Oracle Oracle Analytics Risk Matrix: Analytics Server (Bouncy Castle Java Library) — CVE-2023-33202
vendor_oracle·2025-01-15·CVSS 5.5
CVE-2023-33202 [MEDIUM] Oracle Oracle Analytics Risk Matrix: Analytics Server (Bouncy Castle Java Library) — CVE-2023-33202
Oracle Oracle Analytics Risk Matrix: Analytics Server (Bouncy Castle Java Library) vulnerability
CVE: CVE-2023-33202
CVSS: 5.5
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpujan2025 (JAN 2025)
Oracle
Oracle Oracle Analytics Risk Matrix: Analytics Server (Bouncy Castle Java Library) — CVE-2023-33202
vendor_oracle·2024-07-15·CVSS 5.5
CVE-2023-33202 [MEDIUM] Oracle Oracle Analytics Risk Matrix: Analytics Server (Bouncy Castle Java Library) — CVE-2023-33202
Oracle Oracle Analytics Risk Matrix: Analytics Server (Bouncy Castle Java Library) vulnerability
CVE: CVE-2023-33202
CVSS: 5.5
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpujul2024 (JUL 2024)
Red Hat
bc-java: Out of memory while parsing ASN.1 crafted data in org.bouncycastle.openssl.PEMParser class
vendor_redhat·2023-11-23·CVSS 5.5
CVE-2023-33202 [MEDIUM] CWE-400 bc-java: Out of memory while parsing ASN.1 crafted data in org.bouncycastle.openssl.PEMParser class
bc-java: Out of memory while parsing ASN.1 crafted data in org.bouncycastle.openssl.PEMParser class
Bouncy Castle for Java before 1.73 contains a potential Denial of Service (DoS) issue within the Bouncy Castle org.bouncycastle.openssl.PEMParser class. This class parses OpenSSL PEM encoded streams containing X.509 certificates, PKCS8 encoded keys, and PKCS7 objects. Parsing a file that has crafted ASN.1 data through the PEMParser causes an OutOfMemoryError, which can enable a denial of service attack. (For users of the FIPS Java API: BC-FJA 1.0.2.3 and earlier are affected; BC-FJA 1.0.2.4 is fixed.)
A flaw was found in Bouncy Castle for the Java pkix module, which is vulnerable to a potential Denial of Service (DoS) issue within the org.bouncycastle.openssl.PEMParser class. This class pa
Debian
CVE-2023-33202: bouncycastle - Bouncy Castle for Java before 1.73 contains a potential Denial of Service (DoS) ...
vendor_debian·2023·CVSS 5.5
CVE-2023-33202 [MEDIUM] CVE-2023-33202: bouncycastle - Bouncy Castle for Java before 1.73 contains a potential Denial of Service (DoS) ...
Bouncy Castle for Java before 1.73 contains a potential Denial of Service (DoS) issue within the Bouncy Castle org.bouncycastle.openssl.PEMParser class. This class parses OpenSSL PEM encoded streams containing X.509 certificates, PKCS8 encoded keys, and PKCS7 objects. Parsing a file that has crafted ASN.1 data through the PEMParser causes an OutOfMemoryError, which can enable a denial of service attack. (For users of the FIPS Java API: BC-FJA 1.0.2.3 and earlier are affected; BC-FJA 1.0.2.4 is fixed.)
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 1.77-1)
sid: resolved (fixed in 1.77-1)
trixie: resolved (fixed in 1.77-1)
No detection rules found.
No public exploits indexed.
https://bouncycastle.orghttps://github.com/bcgit/bc-java/wiki/CVE%E2%80%902023%E2%80%9033202https://github.com/bcgit/bc-java/wiki/CVE-2023-33202https://security.netapp.com/advisory/ntap-20240125-0001/https://bouncycastle.orghttps://github.com/bcgit/bc-java/wiki/CVE-2023-33202https://security.netapp.com/advisory/ntap-20240125-0001/
2023-11-23
Published