CVE-2019-3955: Buffer Overflow
Dameware Remote Mini Control version 12.1.0.34 and prior contains a unauthenticated remote heap overflow due to the server not properly validating RsaPubKeyLen during key negotiation. An unauthenticated remote attacker can cause a heap buffer overflow by specifying a large RsaPubKeyLen, which could cause a denial of service.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-3955?
CVE-2019-3955 has been classified with a high severity due to the potential for unauthenticated remote code execution.
How do I fix CVE-2019-3955?
To fix CVE-2019-3955, update Dameware Remote Mini Control to version 12.1.0.35 or later.
What type of vulnerability is CVE-2019-3955?
CVE-2019-3955 is a remote heap overflow vulnerability caused by improper validation of the RsaPubKeyLen parameter.
Who is affected by CVE-2019-3955?
CVE-2019-3955 affects users of Dameware Remote Mini Control versions 12.1.0.34 and prior.
Can CVE-2019-3955 be exploited remotely?
Yes, CVE-2019-3955 can be exploited remotely by an unauthenticated attacker.