search menu icon-carat-right cmu-wordmark

CERT Coordination Center

RSA BSAFE libraries denial of service vulnerability

Vulnerability Note VU#754281

Original Release Date: 2007-05-22 | Last Revised: 2007-12-19

Overview

The RSA BSAFE Crypto-C and Cert-C libraries contain a denial-of-service vulnerability.

Description

RSA BSAFE products include software libraries that developers can use to implement cryptography in their applications.

The RSA BSAFE Crypto-C and Cert-C libraries contain a denial-of-service vulnerability. Note that these libraries may be used in third-party applications that are not distributed by RSA.

Impact

A remote, unauthenticated attacker may be able to create a denial-of-service condition.

Solution

Update
RSA has released Crypto-C 6.3.1 and Cert-C 2.8 to address this issue. For more information about obtaining updated software, contact RSA and reference Bug ID 46337.

Vendor Information

754281
 

View all 93 vendors View less vendors


CVSS Metrics

Group Score Vector
Base 0 AV:--/AC:--/Au:--/C:--/I:--/A:--
Temporal 0 E:ND/RL:ND/RC:ND
Environmental 0 CDP:ND/TD:ND/CR:ND/IR:ND/AR:ND

References

Acknowledgements

Thanks to Cisco Systems for reporting this vulnerability.

This document was written by Ryan Giobbi.

Other Information

CVE IDs: CVE-2006-3894
Severity Metric: 0.13
Date Public: 2007-05-22
Date First Published: 2007-05-22
Date Last Updated: 2007-12-19 15:56 UTC
Document Revision: 18

Sponsored by CISA.