Back to Database
Status published
High
CVE-2019-17359
The ASN.1 parser in Bouncy Castle Crypto (aka BC Java)...
Vulnerability Description
The ASN.1 parser in Bouncy Castle Crypto (aka BC Java) 1.63 can trigger a large attempted memory allocation, and resultant OutOfMemoryError error, via crafted ASN.1 data. This is fixed in 1.64.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-17359
Credits & Attribution
No credits recorded in the NVD database.
References
- https://lists.apache.org/thread.html/r467ade3fef3493f1fff1a68a256d087874e1f858ad1de7a49fe05d27%40%3Ccommits.tomee.apache.org%3E
- https://lists.apache.org/thread.html/r4d475dcaf4f57115fa57d8e06c3823ca398b35468429e7946ebaefdc%40%3Ccommits.tomee.apache.org%3E
- https://lists.apache.org/thread.html/r16c3a90cb35ae8a9c74fd5c813c16d6ac255709c9f9d71cd409e007d%40%3Ccommits.tomee.apache.org%3E
- https://lists.apache.org/thread.html/r02f887807a49cfd1f1ad53f7a61f3f8e12f60ba2c930bec163031209%40%3Ccommits.tomee.apache.org%3E
- https://lists.apache.org/thread.html/r91b07985b1307390a58c5b9707f0b28ef8e9c9e1c86670459f20d601%40%3Ccommits.tomee.apache.org%3E
- https://lists.apache.org/thread.html/re60f980c092ada4bfe236dcfef8b6ca3e8f3b150fc0f51b8cc13d59d%40%3Ccommits.tomee.apache.org%3E
- https://lists.apache.org/thread.html/r8ecb5b76347f84b6e3c693f980dbbead88c25f77b815053c4e6f2c30%40%3Ccommits.tomee.apache.org%3E
- https://lists.apache.org/thread.html/r79b6a6aa0dd1aeb57bd253d94794bc96f1ec005953c4bd5414cc0db0%40%3Ccommits.tomee.apache.org%3E
- https://www.oracle.com/security-alerts/cpuapr2020.html
- https://www.bouncycastle.org/releasenotes.html
- https://www.oracle.com/security-alerts/cpujul2020.html
- https://www.oracle.com/security-alerts/cpujan2020.html
- https://www.bouncycastle.org/latest_releases.html
- https://security.netapp.com/advisory/ntap-20191024-0006/
- https://www.oracle.com/security-alerts/cpuoct2020.html
- https://www.oracle.com/security-alerts/cpujan2021.html
More from bouncycastle
View All →CVE-2022-45146
An issue was discovered in the FIPS Java API of...
Medium
5.5
CVE-2020-28052
An issue was discovered in Legion of the Bouncy Castle...
High
8.1
CVE-2020-26939
In Legion of the Bouncy Castle BC before 1.61 and...
Medium
5.3
CVE-2020-15522
Bouncy Castle BC Java before 1.66, BC C# .NET before...
Medium
5.9
CVE-2018-1000613
Legion of the Bouncy Castle Legion of the Bouncy Castle...
Critical
9.8
Affected Vendor
bouncycastle
View all reports →Affected Software
bc-java, tomee, active iq unified manager, oncommand api services, oncommand workflow automation, service level manager, business process management suite, communications convergence, communications diameter signaling router, communications session route manager, data integrator, financial services analytical applications infrastructure, flexcube private banking, hospitality guest access, managed file transfer, peoplesoft enterprise hcm global payroll switzerland, peoplesoft enterprise peopletools, retail xstore point of service, soa suite, webcenter portal, weblogic server
Vulnerable Versions:
1.63, 7.0.7, 7.1.2, 8.0.1, 7.3, 9.5, 12.2.1.3.0, 12.2.1.4.0, 3.0.1.0, 8.0.0, 8.2.0, 8.0.6, 12.0.0, 12.1.0, 4.2.0, 9.2, 8.56, 8.57, 8.58, 18.0.1, 11.1.1.9.0
Timeline
Official Publish:
October 8th, 2019
Last Modified:
August 5th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.