CVE-2019-3956: Input Validation
Dameware Remote Mini Control version 12.1.0.34 and prior contains an unauthenticated remote buffer over-read due to the server not properly validating CltDHPubKeyLen during key negotiation, which could crash the application or leak sensitive information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-3956?
CVE-2019-3956 is rated as a critical vulnerability due to its potential to cause application crashes and information leaks.
How do I fix CVE-2019-3956?
To mitigate CVE-2019-3956, upgrade to Dameware Remote Mini Control version 12.1.0.35 or later.
What type of vulnerability is CVE-2019-3956?
CVE-2019-3956 is categorized as an unauthenticated remote buffer over-read vulnerability.
What could happen if CVE-2019-3956 is exploited?
Exploitation of CVE-2019-3956 could lead to application crashes or the disclosure of sensitive information.
Which versions of Dameware Remote Mini Control are affected by CVE-2019-3956?
Dameware Remote Mini Control versions 12.1.0.34 and earlier are affected by CVE-2019-3956.