NA

CVE-2024-34447

Published: 03/05/2024 Updated: 14/05/2024

Vulnerability Summary

An issue exists in Bouncy Castle Java Cryptography APIs before BC 1.78. When endpoint identification is enabled in the BCJSSE and an SSL socket is created without an explicit hostname (as happens with HttpsURLConnection), hostname verification could be performed against a DNS-resolved IP address in some situations, opening up a possibility of DNS poisoning.

Vendor Advisories

Debian Bug report logs - #1070655 bouncycastle: CVE-2024-29857 CVE-2024-30171 CVE-2024-30172 CVE-2024-34447 Package: src:bouncycastle; Maintainer for src:bouncycastle is Debian Java Maintainers <pkg-java-maintainers@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Mon, 6 May 2024 ...