CVE-2019-3728: High severity dell bsafe crypto-c micro edition vulnerability
RSA BSAFE Crypto-C Micro Edition versions from 4.0.0.0 before 4.0.5.4 and from 4.1.0 before 4.1.4, RSA BSAFE Micro Edition Suite versions from 4.0.0 before 4.0.13 and from 4.1.0 before 4.4 and RSA Crypto-C versions from 6.0.0 through 6.4. are vulnerable to an out-of-bounds read vulnerability when processing DSA signature. A malicious remote user could potentially exploit this vulnerability to cause a crash in the library of the affected system.
Other sources
RSA BSAFE Crypto-C Micro Edition versions prior to 4.0.5.4 (in 4.0.x) and 4.1.4 (in 4.1.x) and RSA BSAFE Micro Edition Suite versions prior to 4.0.13 (in 4.0.x) and prior to 4.4 (in 4.1.x, 4.2.x, 4.3.x) are vulnerable to a Buffer Over-read vulnerability when processing DSA signature. A malicious remote user could potentially exploit this vulnerability to cause a crash in the library of the affected system.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-3728?
CVE-2019-3728 is a vulnerability in RSA BSAFE Crypto-C Micro Edition and RSA BSAFE Micro Edition Suite that allows for a buffer over-read when processing DSA signatures.
Which versions of Dell BSAFE Crypto-C Micro Edition are affected?
Dell BSAFE Crypto-C Micro Edition versions prior to 4.0.5.4 (in 4.0.x) and 4.1.4 (in 4.1.x) are affected by CVE-2019-3728.
Which versions of Dell BSAFE Micro Edition Suite are affected?
Dell BSAFE Micro Edition Suite versions prior to 4.0.13 (in 4.0.x) and prior to 4.4 (in 4.1.x, 4.2.x, 4.3.x) are affected by CVE-2019-3728.
What is the severity of CVE-2019-3728?
CVE-2019-3728 has a severity rating of 7.5 (high).
How can I fix CVE-2019-3728?
To fix CVE-2019-3728, you should update to Dell BSAFE Crypto-C Micro Edition 4.0.5.4 (or later) or 4.1.4 (or later), and Dell BSAFE Micro Edition Suite 4.0.13 (or later) or 4.4 (or later).