CVE-2018-11058

CWE-125Out-of-bounds Read7 documents4 sources
Severity
9.8CRITICAL
EPSS
1.6%
top 18.18%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 14
Latest updateMay 13

Description

RSA BSAFE Micro Edition Suite, versions prior to 4.0.11 (in 4.0.x) and prior to 4.1.6 (in 4.1.x), and RSA BSAFE Crypto-C Micro Edition, version prior to 4.0.5.3 (in 4.0.x) contain a Buffer Over-Read vulnerability when parsing ASN.1 data. A remote attacker could use maliciously constructed ASN.1 data that would result in such issue.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages15 packages

CVEListV5rsa/bsafe_micro_edition_suiteunspecified4.0.11+1
CVEListV5rsa/bsafe_crypto-c_micro_editionunspecified4.0.5.3
NVDdell/bsafe_crypto-c4.0.04.0.5.3
NVDdell/bsafe4.0.04.0.11+1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-6pm8-q9vc-vxxj: RSA BSAFE Micro Edition Suite, versions prior to 42022-05-13
CVEList
CVE-2018-11058: RSA BSAFE Micro Edition Suite, versions prior to 42018-09-14

📋Vendor Advisories

4
Oracle
Oracle Oracle TimesTen In-Memory Database Risk Matrix: EM TimesTen plugin (RSA BSAFE Crypto-C) — CVE-2018-110582020-10-15
Oracle
Oracle Oracle Communications Applications Risk Matrix: Platform (RSA BSAFE) — CVE-2018-110582020-07-15
Oracle
Oracle Oracle Enterprise Manager Risk Matrix: Processing (Oracle Instant Client) — CVE-2018-110582020-04-15
Oracle
Oracle Oracle Communications Applications Risk Matrix: Database Client (NZ) — CVE-2018-110582020-01-15