CVE-2019-3955

Severity CVSS v4.0:
Pending analysis
Type:
CWE-787 Out-of-bounds Write
Publication date:
07/06/2019
Last modified:
24/08/2020

Description

Dameware Remote Mini Control version 12.1.0.34 and prior contains a unauthenticated remote heap overflow due to the server not properly validating RsaPubKeyLen during key negotiation. An unauthenticated remote attacker can cause a heap buffer overflow by specifying a large RsaPubKeyLen, which could cause a denial of service.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:dameware:remote_mini_control:*:*:*:*:*:*:*:* 12.1.0.34 (including)


References to Advisories, Solutions, and Tools