SB2019100109 - Buffer Over-read in RSA BSAFE Crypto-C Micro Edition and Micro Edition Suite



SB2019100109 - Buffer Over-read in RSA BSAFE Crypto-C Micro Edition and Micro Edition Suite

Published: October 1, 2019

Security Bulletin ID SB2019100109
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Buffer Over-read (CVE-ID: CVE-2019-3728)

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to buffer over-read issue when processing DSA signature. A remote attacker can cause a crash in the library of the affected system.

This vulnerability affects the following versions:
  • RSA BSAFE Crypto-C Micro Edition - versions prior to 4.0.5.4 (in 4.0.x) and prior 4.1.4 (in 4.1.x)
  • RSA BSAFE Micro Edition Suite - versions prior to 4.0.13 (in 4.0.x) and prior to 4.4 (in 4.1.x, 4.2.x, 4.3.x)


Remediation

Install update from vendor's website.