CVE-2018-11056: Medium severity Dell Bsafe vulnerability
RSA BSAFE Micro Edition Suite, prior to 4.1.6.1 (in 4.1.x), and RSA BSAFE Crypto-C Micro Edition versions prior to 4.0.5.3 (in 4.0.x) contain an Uncontrolled Resource Consumption ('Resource Exhaustion') vulnerability when parsing ASN.1 data. A remote attacker could use maliciously constructed ASN.1 data that would exhaust the stack, potentially causing a Denial Of Service.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2018-11056?
CVE-2018-11056 refers to an Uncontrolled Resource Consumption vulnerability in RSA BSAFE Micro Edition Suite and RSA BSAFE Crypto-C Micro Edition.
What is the severity of CVE-2018-11056?
The severity of CVE-2018-11056 is medium with a severity value of 6.5.
Which software products are affected by CVE-2018-11056?
CVE-2018-11056 affects Dell BSAFE Micro Edition Suite, Dell BSAFE Crypto-C Micro Edition, Oracle Application Testing Suite, Oracle Communications Analytics, Oracle Communications Ip Service Activator, Oracle Core Rdbms, Oracle Enterprise Manager Ops Center, Oracle Goldengate Application Adapters, Oracle Jd Edwards Enterpriseone Tools, Oracle Real User Experience Insight, Oracle Retail Predictive Application Server, Oracle Security Service, and Oracle TimesTen In-Memory Database.
How can a remote attacker exploit CVE-2018-11056?
A remote attacker can exploit CVE-2018-11056 by using maliciously constructed ASN.1 data.
Where can I find more information about CVE-2018-11056?
You can find more information about CVE-2018-11056 at the following references: - [Security Mailing List](http://seclists.org/fulldisclosure/2018/Aug/46) - [Oracle Security Alerts](https://www.oracle.com/security-alerts/cpuapr2020.html) - [Oracle Security Alerts](https://www.oracle.com/security-alerts/cpujan2020.html)