Out-of-bounds read in RSA BSAFE Crypto-C and RSA BSAFE Micro Edition Suite - CVE-2018-11058
Published: October 1, 2019 / Updated: October 27, 2020
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to a boundary condition when parsing ASN.1 data. A remote attacker can use a specially constructed ASN.1 data, trigger out-of-bounds read error and read contents of memory on the system.
This vulnerability affects the following versions of RSA BSAFE Crypto-C Micro Edition:
- version prior to 4.0.5.3 (in 4.0.x)
Affected software
RSA BSAFE Micro Edition Suite
Oracle Communications IP Service Activator
Oracle Communications Analytics
Oracle Real User Experience Insight
PeopleSoft Enterprise PeopleTools
JD Edwards EnterpriseOne Tools
Oracle GoldenGate Application Adapters
Oracle WebLogic Server
Oracle Retail Predictive Application Server
Oracle Security Service
Oracle Access Manager
Oracle Database Server
Oracle TimesTen In-Memory Database
Oracle Enterprise Manager Ops Center
Oracle Application Testing Suite
How to mitigate CVE-2018-11058
RSA BSAFE Micro Edition Suite - addressed in versions 4.0.11, 4.1.6
Oracle TimesTen In-Memory Database - update to 18.1.4.1.0
External References
Related Security Bulletins
- Out-of-bounds read in RSA BSAFE Micro Edition Suite and Crypto-C Micro Edition
- Information disclosure in Oracle Communications IP Service Activator
- Multiple vulnerabilities in Oracle Enterprise Manager Ops Center
- Out-of-bounds read in Oracle Real User Experience Insight
- Multiple vulnerabilities in JD Edwards EnterpriseOne Tools
- Out-of-bounds read in Oracle Retail Predictive Application Server
- Multiple vulnerabilities in Oracle Communications Analytics
- Multiple vulnerabilities in Oracle WebLogic Server
- Multiple vulnerabilities in Oracle TimesTen In-Memory Database
- Multiple vulnerabilities in Oracle GoldenGate Application Adapters
- Out-of-bounds read in Oracle Access Manager
- Multiple vulnerabilities in Oracle Application Testing Suite
- Multiple vulnerabilities in PeopleSoft Enterprise PeopleTools
- Multiple vulnerabilities in Oracle Database Server
- Out-of-bounds read in Oracle Security Service