CVE-2013-1624

medium
Published 2013-02-08 ยท Modified 2024-12-05
CVSS v3
โ€”
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
4.0

Description

Improper Input Validation in Bouncy Castle

Predictions

Exploit likelihood
20%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No mitigations published for this CVE yet.

The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ€” if you've already worked around this in production โ€” publish your fix to the community-verified tier.

โœš Propose a mitigation on Community โ†’ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here with source_tier=community-verified.

OS impact

debian Debian Fixed 5 releases
VersionStatusFixed in
trixie Fixed 1.48+dfsg-2
sid Fixed 1.48+dfsg-2
forky Fixed 1.48+dfsg-2
bullseye Fixed 1.48+dfsg-2
bookworm Fixed 1.48+dfsg-2

Package impact

EcosystemPackageVulnerableFixed
java Mavenorg.bouncycastle:bcprov-jdk15on<1.481.48

Application impact

VendorProductVersionsFixed
bouncycastlebc-java1.01
bouncycastlebc-java1.02
bouncycastlebc-java1.03
bouncycastlebc-java1.04
bouncycastlebc-java1.05
bouncycastlebc-java1.06
bouncycastlebc-java1.07
bouncycastlebc-java1.08
bouncycastlebc-java1.09
bouncycastlebc-java1.10
bouncycastlebc-java1.11
bouncycastlebc-java1.12
bouncycastlebc-java1.13
bouncycastlebc-java1.14
bouncycastlebc-java1.15
bouncycastlebc-java1.16
bouncycastlebc-java1.17
bouncycastlebc-java1.18
bouncycastlebc-java1.19
bouncycastlebc-java1.20
bouncycastlebc-java1.21
bouncycastlebc-java1.22
bouncycastlebc-java1.23
bouncycastlebc-java1.24
bouncycastlebc-java1.25
bouncycastlebc-java1.26
bouncycastlebc-java1.27
bouncycastlebc-java1.28
bouncycastlebc-java1.29
bouncycastlebc-java1.30
bouncycastlebc-java1.31
bouncycastlebc-java1.32
bouncycastlebc-java1.33
bouncycastlebc-java1.34
bouncycastlebc-java1.35
bouncycastlebc-java1.36
bouncycastlebc-java1.37
bouncycastlebc-java1.38
bouncycastlebc-java1.39
bouncycastlebc-java1.40
bouncycastlebc-java1.41
bouncycastlebc-java1.42
bouncycastlebc-java1.43
bouncycastlebc-java1.44
bouncycastlebc-java1.45
bouncycastlebc-java1.46
bouncycastlebc-java1.47
bouncycastlelegion-of-the-bouncy-castle-c\#-cryptography-api0.0
bouncycastlelegion-of-the-bouncy-castle-c\#-cryptography-api1.0
bouncycastlelegion-of-the-bouncy-castle-c\#-cryptography-api1.1
bouncycastlelegion-of-the-bouncy-castle-c\#-cryptography-api1.2
bouncycastlelegion-of-the-bouncy-castle-c\#-cryptography-api1.3
bouncycastlelegion-of-the-bouncy-castle-c\#-cryptography-api1.4
bouncycastlelegion-of-the-bouncy-castle-c\#-cryptography-api1.5
bouncycastlelegion-of-the-bouncy-castle-c\#-cryptography-api1.6.1
bouncycastlelegion-of-the-bouncy-castle-c\#-cryptography-api1.7

References

CWEs

CWE-310

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.