First published: Fri Aug 31 2018(Updated: )
RSA BSAFE Micro Edition Suite, prior to 4.1.6.1 (in 4.1.x), and RSA BSAFE Crypto-C Micro Edition versions prior to 4.0.5.3 (in 4.0.x) contain an Uncontrolled Resource Consumption ('Resource Exhaustion') vulnerability when parsing ASN.1 data. A remote attacker could use maliciously constructed ASN.1 data that would exhaust the stack, potentially causing a Denial Of Service.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell BSAFE | >=4.1.0<4.1.6.1 | |
Dell BSAFE Crypto-C | >=4.0.0<4.0.5.3 | |
Oracle Application Testing Suite | =13.3.0.1 | |
oracle communications analytics | =12.1.1 | |
Oracle Communications IP Service Activator | =7.3.0 | |
Oracle Communications IP Service Activator | =7.4.0 | |
Oracle Core RDBMS | =11.2.0.4 | |
Oracle Core RDBMS | =12.1.0.2 | |
Oracle Core RDBMS | =12.2.0.1 | |
Oracle Core RDBMS | =18c | |
Oracle Core RDBMS | =19c | |
Oracle Enterprise Manager Ops Center | =12.3.3 | |
Oracle Enterprise Manager Ops Center | =12.4.0 | |
Oracle GoldenGate Application Adapters | =12.3.2.1.0 | |
Oracle JD Edwards EnterpriseOne Tools | =9.2 | |
oracle real user experience insight | =13.1.2.1 | |
oracle real user experience insight | =13.2.3.1 | |
oracle real user experience insight | =13.3.1.0 | |
Oracle Retail Predictive Application Server | =15.0.3 | |
Oracle Retail Predictive Application Server | =16.0.3.0 | |
Oracle Security Service | =11.1.1.9.0 | |
Oracle Security Service | =12.1.3.0.0 | |
Oracle Security Service | =12.2.1.3.0 | |
Oracle TimesTen In-Memory Database | <18.1.4.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-11056 refers to an Uncontrolled Resource Consumption vulnerability in RSA BSAFE Micro Edition Suite and RSA BSAFE Crypto-C Micro Edition.
The severity of CVE-2018-11056 is medium with a severity value of 6.5.
CVE-2018-11056 affects Dell BSAFE Micro Edition Suite, Dell BSAFE Crypto-C Micro Edition, Oracle Application Testing Suite, Oracle Communications Analytics, Oracle Communications Ip Service Activator, Oracle Core Rdbms, Oracle Enterprise Manager Ops Center, Oracle Goldengate Application Adapters, Oracle Jd Edwards Enterpriseone Tools, Oracle Real User Experience Insight, Oracle Retail Predictive Application Server, Oracle Security Service, and Oracle TimesTen In-Memory Database.
A remote attacker can exploit CVE-2018-11056 by using maliciously constructed ASN.1 data.
You can find more information about CVE-2018-11056 at the following references: - [Security Mailing List](http://seclists.org/fulldisclosure/2018/Aug/46) - [Oracle Security Alerts](https://www.oracle.com/security-alerts/cpuapr2020.html) - [Oracle Security Alerts](https://www.oracle.com/security-alerts/cpujan2020.html)