SB2018083108 - Resource exhaustion in RSA BSAFE Micro Edition Suite and Crypto-C Micro Edition
Published: August 31, 2018 Updated: October 1, 2019
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Resource exhaustion (CVE-ID: CVE-2018-11056)
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper parsing of ASN.1 data. A remote authenticated attacker can use a specially constructed ASN.1 data, trigger resource exhaustion and perform a denial of service (DoS) attack.
This vulnerability affects the following versions of RSA BSAFE Crypto-C Micro Edition:
- versions prior to 4.0.5.3 (in 4.0.x)
Remediation
Install update from vendor's website.