Legion of the Bouncy Castle Inc. Bouncy Castle
cpe:2.3:a:bouncycastle:legion-of-the-bouncy-castle:*:*:*:*:*:*:*
- 2.1.0
An out-of-bounds write vulnerability has been identified in Legion of the Bouncy Castle Inc. Bouncy Castle for Java BC-FIPS, specifically in version 2.1.0. This vulnerability arises in the JCE Cipher.doFinal() method, which can unintentionally overwrite input data when the input and output arrays are the same, and the output is offset differently from the input. This misalignment can lead to the creation of corrupted encryption or decryption results.
Exploitation of this vulnerability can cause incorrect encryption or decryption, resulting in corrupted data.
Users can upgrade to Bouncy Castle for Java version 2.1.1 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.