First published: Tue May 22 2007(Updated: )
The RSA Crypto-C before 6.3.1 and Cert-C before 2.8 libraries, as used by RSA BSAFE, multiple Cisco products, and other products, allows remote attackers to cause a denial of service via malformed ASN.1 objects.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
BSAFE Cert-C | <=2.7 | |
Dell BSAFE Crypto-C | <=6.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-3894 is classified as a critical vulnerability as it allows remote attackers to cause a denial of service.
To fix CVE-2006-3894, update to RSA BSAFE Crypto-C version 6.3.1 or later, and BSAFE Cert-C version 2.8 or later.
CVE-2006-3894 affects older versions of RSA BSAFE Crypto-C and Cert-C libraries integrated into various Cisco and Dell products.
The potential impact of CVE-2006-3894 is a denial of service, which could disrupt service availability for applications using the vulnerable libraries.
While CVE-2006-3894 was reported in 2006, it remains relevant for organizations using unsupported versions of affected software.