CVE-2015-0536: High severity rsa bsafe vulnerability
EMC RSA BSAFE Micro Edition Suite (MES) 4.0.x before 4.0.8 and 4.1.x before 4.1.3 and RSA BSAFE SSL-C 2.8.9 and earlier, when client authentication and an ephemeral Diffie-Hellman ciphersuite are enabled, allow remote attackers to cause a denial of service (daemon crash) via a ClientKeyExchange message with a length of zero, a similar issue to CVE-2015-1787.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-0536?
CVE-2015-0536 is classified as a denial of service vulnerability.
How do I fix CVE-2015-0536?
The recommended fix for CVE-2015-0536 is to update to EMC RSA BSAFE Micro Edition Suite version 4.0.8 or 4.1.3 or later, and ensure the SSL-C version is updated beyond 2.8.9.
What systems are affected by CVE-2015-0536?
CVE-2015-0536 affects EMC RSA BSAFE Micro Edition Suite versions prior to 4.0.8 and 4.1.3, and RSA BSAFE SSL-C versions 2.8.9 and earlier.
What type of attack does CVE-2015-0536 permit?
CVE-2015-0536 allows remote attackers to cause a denial of service by crashing the daemon.
When was CVE-2015-0536 disclosed?
CVE-2015-0536 was disclosed in August 2015.