The ASN.1 parser in Bouncy Castle Crypto (aka BC Java) 1.63 can trigger a large attempted memory allocation, and resultant OutOfMemoryError error, via crafted ASN.1 data. This is fixed in 1.64.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Apache
Subscribe
|
Tomee
Subscribe
|
|
Bouncycastle
Subscribe
|
Bc-java
Subscribe
|
|
Netapp
Subscribe
|
|
|
Oracle
Subscribe
|
Business Process Management Suite
Subscribe
Communications Convergence
Subscribe
Communications Diameter Signaling Router
Subscribe
Communications Session Route Manager
Subscribe
Data Integrator
Subscribe
Financial Services Analytical Applications Infrastructure
Subscribe
Flexcube Private Banking
Subscribe
Hospitality Guest Access
Subscribe
Managed File Transfer
Subscribe
Peoplesoft Enterprise Hcm Global Payroll Switzerland
Subscribe
Peoplesoft Enterprise Peopletools
Subscribe
Retail Xstore Point Of Service
Subscribe
Soa Suite
Subscribe
Webcenter Portal
Subscribe
Weblogic Server
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-0682 | The ASN.1 parser in Bouncy Castle Crypto (aka BC Java) 1.63 can trigger a large attempted memory allocation, and resultant OutOfMemoryError error, via crafted ASN.1 data. This is fixed in 1.64. |
Github GHSA |
GHSA-2mh8-gx2m-mr75 | Out-of-Memory Error in Bouncy Castle Crypto |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 12 May 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Bouncycastle bc-java
|
|
| CPEs | cpe:2.3:a:bouncycastle:bc-java:1.63:*:*:*:*:*:*:* | |
| Vendors & Products |
Bouncycastle legion-of-the-bouncy-castle-java-crytography-api
|
Bouncycastle bc-java
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T01:40:15.255Z
Reserved: 2019-10-08T00:00:00.000Z
Link: CVE-2019-17359
No data.
Status : Modified
Published: 2019-10-08T14:15:10.573
Modified: 2025-05-12T17:37:16.527
Link: CVE-2019-17359
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA