Out-of-bounds read in RSA BSAFE Crypto-C and RSA BSAFE Micro Edition Suite - CVE-2018-11058

 

Out-of-bounds read in RSA BSAFE Crypto-C and RSA BSAFE Micro Edition Suite - CVE-2018-11058

Published: October 1, 2019 / Updated: October 27, 2020


Vulnerability identifier: #VU21465
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-11058
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to a boundary condition when parsing ASN.1 data. A remote attacker can use a specially constructed ASN.1 data, trigger out-of-bounds read error and read contents of memory on the system.

This vulnerability affects the following versions of RSA BSAFE Crypto-C Micro Edition:

  • version prior to 4.0.5.3 (in 4.0.x)


Affected software

RSA BSAFE Crypto-C
RSA BSAFE Micro Edition Suite
Oracle Communications IP Service Activator
Oracle Communications Analytics
Oracle Real User Experience Insight
PeopleSoft Enterprise PeopleTools
JD Edwards EnterpriseOne Tools
Oracle GoldenGate Application Adapters
Oracle WebLogic Server
Oracle Retail Predictive Application Server
Oracle Security Service
Oracle Access Manager
Oracle Database Server
Oracle TimesTen In-Memory Database
Oracle Enterprise Manager Ops Center
Oracle Application Testing Suite

How to mitigate CVE-2018-11058

Install updates from vendor's website.

RSA BSAFE Crypto-C - update to 4.0.5.3
RSA BSAFE Micro Edition Suite - addressed in versions 4.0.11, 4.1.6
Oracle TimesTen In-Memory Database - update to 18.1.4.1.0

External References

Related Security Bulletins