2017 m. birželio 19 d., pirmadienis

ESA-2017-031: RSA BSAFE® Cert-C Improper Certificate Processing Vulnerability

ESA-2017-031: RSA BSAFE® Cert-C Improper Certificate Processing Vulnerability

EMC Identifier: ESA-2017-031

CVE Identifier: CVE-2017-4981

 

Severity Rating: 8.2 (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H)

 

Affected Products: 

RSA BSAFE Cert-C all versions prior to 2.9.0.5  (RSA BSAFE Cert C is End of Primary Support and End of Extended Support per prior notification)

Summary:  

RSA BSAFE Cert-C contains updates designed to address a potential improper certificate processing vulnerability.

 

Details:  

RSA BSAFE Cert-C is affected by a potential improper certificate processing vulnerability. The vulnerability is caused by a faulty certificate processing logic that may potentially cause a crash in RSA BSAFE Cert-C. 

 

Recommendation: 

The following RSA BSAFE Cert-C release contains a resolution to this vulnerability:
•RSA BSAFE Cert-C version 2.9.0.5

 

RSA recommends all customers upgrade at the earliest opportunity. 

 

RSA also reminds customers that RSA BSAFE Cert-C is now End of Primary Support and End of Extended Support per prior notification and customers are strongly advised to migrate to other solutions at the earliest opportunity.

Komentarų nėra:

Rašyti komentarą