CVE-2018-1232

Severity CVSS v4.0:
Pending analysis
Type:
CWE-787 Out-of-bounds Write
Publication date:
30/03/2018
Last modified:
24/08/2020

Description

RSA Authentication Agent version 8.0.1 and earlier for Web for both IIS and Apache Web Server are impacted by a stack-based buffer overflow which may occur when handling certain malicious web cookies that have invalid formats. The attacker could exploit this vulnerability to crash the authentication agent and cause a denial-of-service situation.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:rsa:authentication_agent_for_web:*:*:*:*:*:apache_web_server:*:* 8.0.1 (including)
cpe:2.3:a:rsa:authentication_agent_for_web:*:*:*:*:*:iis:*:* 8.0.1 (including)