CVE-2019-3729Stack-based Buffer Overflow in Dell RSA Bsafe MES

Severity
2.4LOWNVD
EPSS
0.1%
top 69.68%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 30
Latest updateMay 24

Description

RSA BSAFE Micro Edition Suite versions prior to 4.4 (in 4.0.x, 4.1.x, 4.2.x and 4.3.x) are vulnerable to a Heap-based Buffer Overflow vulnerability when parsing ECDSA signature. A malicious user with adjacent network access could potentially exploit this vulnerability to cause a crash in the library of the affected system.

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:LExploitability: 0.9 | Impact: 1.4

Affected Packages2 packages

NVDdell/bsafe_micro-edition-suite4.0.04.0.13+1
CVEListV5dell/rsa_bsafe_mesunspecified4.4

🔴Vulnerability Details

2
GHSA
GHSA-ff5p-8cgp-p5jc: RSA BSAFE Micro Edition Suite versions prior to 42022-05-24
CVEList
CVE-2019-3729: RSA BSAFE Micro Edition Suite versions prior to 42019-09-30

💥Exploits & PoCs

1
Exploit-DB
Fastweb Fastgate 0.00.81 - Remote Code Execution2019-11-13

📋Vendor Advisories

20
Red Hat
chromium-browser: parameter passing error in media player leading to unauthorized access2019-04-30
Red Hat
sqlite: out-of-bounds access due to the use of 32-bit memory allocator interfaces2019-04-30
Red Hat
chromium-browser: Use after free in Blink2019-04-23
Red Hat
chromium-browser: Use after free in Blink2019-04-23
Red Hat
chromium-browser: Heap buffer overflow in Angle on Windows2019-04-23

💬Community

2
Bugzilla
CVE-2019-5826 chromium-browser: Use-after-free in IndexedDB2019-05-07
Bugzilla
CVE-2019-5825 chromium-browser: Out-of-bounds write in V82019-05-07
CVE-2019-3729 — Stack-based Buffer Overflow in Dell | cvebase