SB2018111510 - Denial of service in Dell RSA BSAFE Micro Edition Suite
Published: November 15, 2018
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper input validation (CVE-ID: CVE-2018-15769)
The vulnerability allows a remote attacker to cause DoS condition.
The vulnerability exists due to improper management of keys when an Ephemeral or Anonymous Diffie-Hellman (DHE or ADH) cipher suite is used A remote attacker with access to a Transport Layer Security (TLS) server can send a very large prime value to a targeted TLS client and cause the service to crash.
Remediation
Install update from vendor's website.