The vendor explicitly identifies these products as affected by this CVE.
- bctls-jdk18on as a component of Red Hat Fuse 7
- openvox-server.src as a component of Red Hat Satellite 6
- Summary
- A flaw was found in Bouncy Castle for Java. The DTLS (Datagram Transport Layer Security) handshake reassembler allocates buffers based on an unchecked 24-bit length value. A remote attacker could exploit this vulnerability by sending a specially crafted DTLS handshake message, leading to excessive memory allocation and a denial of service (DoS) condition.
- Remediation
- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
