SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

 

Vulnerability Note VU#754281

RSA BSAFE libraries denial of service vulnerability

Overview

The RSA BSAFE Crypto-C and Cert-C libraries contain a denial-of-service vulnerability.

I. Description

RSA BSAFE products include software libraries that developers can use to implement cryptography in their applications.

The RSA BSAFE Crypto-C and Cert-C libraries contain a denial-of-service vulnerability. Note that these libraries may be used in third-party applications that are not distributed by RSA.

II. Impact

A remote, unauthenticated attacker may be able to create a denial-of-service condition.

III. Solution

Update

RSA has released Crypto-C 6.3.1 and Cert-C 2.8 to address this issue. For more information about obtaining updated software, contact RSA and reference Bug ID 46337.

Systems Affected

VendorStatusDate Updated
3com, Inc.Unknown7-Dec-2006
AlcatelUnknown7-Dec-2006
Apple Computer, Inc.Unknown7-Dec-2006
AT&TUnknown7-Dec-2006
Avaya, Inc.Unknown7-Dec-2006
Avici Systems, Inc.Unknown7-Dec-2006
Borderware TechnologiesUnknown7-Dec-2006
BroUnknown21-May-2007
Charlotte's Web NetworksUnknown7-Dec-2006
Check Point Software TechnologiesUnknown7-Dec-2006
Chiaro Networks, Inc.Unknown7-Dec-2006
Cisco Systems, Inc.Vulnerable22-May-2007
ClavisterUnknown7-Dec-2006
Computer AssociatesUnknown7-Dec-2006
Computer Associates eTrust Security ManagementUnknown21-May-2007
Conectiva Inc.Unknown7-Dec-2006
Cray Inc.Unknown7-Dec-2006
D-Link Systems, Inc.Unknown7-Dec-2006
Data Connection, Ltd.Unknown7-Dec-2006
Debian GNU/LinuxUnknown7-Dec-2006
EMC, Inc. (formerly Data General Corporation)Vulnerable22-May-2007
Engarde Secure LinuxUnknown7-Dec-2006
Enterasys NetworksUnknown21-May-2007
EricssonUnknown7-Dec-2006
eSoft, Inc.Unknown7-Dec-2006
Extreme NetworksUnknown7-Dec-2006
F5 Networks, Inc.Unknown7-Dec-2006
Fedora ProjectUnknown26-Feb-2007
Force10 Networks, Inc.Unknown7-Dec-2006
Fortinet, Inc.Unknown7-Dec-2006
Foundry Networks, Inc.Not Vulnerable19-Dec-2007
FreeBSD, Inc.Unknown7-Dec-2006
FujitsuUnknown7-Dec-2006
Gentoo LinuxUnknown26-Feb-2007
Global Technology AssociatesUnknown7-Dec-2006
Hewlett-Packard CompanyUnknown7-Dec-2006
HitachiNot Vulnerable24-May-2007
HyperchipUnknown7-Dec-2006
IBM CorporationUnknown7-Dec-2006
IBM Corporation (zseries)Unknown7-Dec-2006
IBM eServerUnknown7-Dec-2006
Immunix Communications, Inc.Unknown7-Dec-2006
Ingrian Networks, Inc.Unknown7-Dec-2006
Intel CorporationUnknown7-Dec-2006
Internet Security Systems, Inc.Unknown7-Dec-2006
IntotoUnknown7-Dec-2006
IP FilterUnknown7-Dec-2006
Juniper Networks, Inc.Unknown7-Dec-2006
Linksys (A division of Cisco Systems)Unknown7-Dec-2006
Lucent TechnologiesUnknown7-Dec-2006
Luminous NetworksUnknown7-Dec-2006
Mandriva, Inc.Unknown26-Feb-2007
McAfeeNot Vulnerable23-May-2007
Microsoft CorporationNot Vulnerable22-May-2007
MontaVista Software, Inc.Unknown26-Feb-2007
Multinet (owned Process Software Corporation)Unknown7-Dec-2006
Multitech, Inc.Unknown7-Dec-2006
NEC CorporationUnknown7-Dec-2006
NetBSDUnknown26-Feb-2007
netfilterUnknown26-Feb-2007
Network Appliance, Inc.Unknown7-Dec-2006
NextHop Technologies, Inc.Unknown7-Dec-2006
NokiaUnknown7-Dec-2006
Nortel Networks, Inc.Not Vulnerable23-May-2007
Novell, Inc.Vulnerable22-May-2007
OpenBSDUnknown26-Feb-2007
Openwall GNU/*/LinuxUnknown26-Feb-2007
QNX, Software Systems, Inc.Unknown7-Dec-2006
Red Hat, Inc.Unknown26-Feb-2007
Redback Networks, Inc.Unknown7-Dec-2006
Riverstone Networks, Inc.Unknown7-Dec-2006
RSA Security, Inc.Vulnerable22-May-2007
Secure Computing Network Security DivisionUnknown7-Dec-2006
Secureworx, Inc.Unknown7-Dec-2006
Silicon Graphics, Inc.Unknown7-Dec-2006
Slackware Linux Inc.Unknown26-Feb-2007
SnortUnknown21-May-2007
Sony CorporationUnknown7-Dec-2006
SourcefireUnknown21-May-2007
StonesoftUnknown7-Dec-2006
Sun Microsystems, Inc.Unknown7-Dec-2006
SUSE LinuxUnknown7-Dec-2006
Symantec, Inc.Unknown7-Dec-2006
The SCO GroupUnknown7-Dec-2006
TippingPoint, Technologies, Inc.Not Vulnerable22-May-2007
Trustix Secure LinuxUnknown26-Feb-2007
TurbolinuxUnknown26-Feb-2007
UbuntuUnknown26-Feb-2007
UnisysUnknown7-Dec-2006
Verisign Unknown27-Feb-2007
Watchguard Technologies, Inc.Unknown7-Dec-2006
Wind River Systems, Inc.Unknown7-Dec-2006
ZyXELUnknown7-Dec-2006

References


http://www.rsa.com/node.aspx?id=1204
http://secunia.com/advisories/25364/

Credit

Thanks to Cisco Systems for reporting this vulnerability.

This document was written by Ryan Giobbi.

Other Information

Date Public05/22/2007
Date First Published05/22/2007 08:56:53 AM
Date Last Updated12/19/2007
CERT Advisory 
CVE NameCVE-2006-3894
US-CERT Technical Alerts 
Metric0.13
Document Revision17

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Produced 2007 by US-CERT, a government organization
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader