Memory corruption in Cisco Email Security Appliance - CVE-2018-15453

 

Memory corruption in Cisco Email Security Appliance - CVE-2018-15453

Published: January 9, 2019 / Updated: January 10, 2019


Vulnerability identifier: #VU16922
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-15453
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause DoS condition.

The vulnerability exists in the Secure/Multipurpose Internet Mail Extensions (S/MIME) Decryption and Verification or S/MIME Public Key Harvesting features due to improper input validation of S/MIME-signed emails. A remote attacker can send a malicious S/MIME-signed email through a targeted device, trigger memory corruption if Decryption and Verification or Public Key Harvesting is configured and cause the filtering process to crash and restart.


Affected software

Cisco Email Security Appliance

How to mitigate CVE-2018-15453

The vulnerability has been addressed in the versions 12.0.0-281, 11.1.1-042, 11.1.1-037, 11.0.2-044.

Cisco Email Security Appliance - addressed in versions 11.0.2 044, 11.1.1 037, 11.1.1 042, 12.0.0 281

External References

Related Security Bulletins