CVE-2018-1232
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
RSA Authentication Agent version 8.0.1 and earlier for Web for both IIS and Apache Web Server are impacted by a stack-based buffer overflow which may occur when handling certain malicious web cookies that have invalid formats. The attacker could exploit this vulnerability to crash the authentication agent and cause a denial-of-service situation.
RSA Authentication Agent en versiones 8.0.1 y anteriores para Web para IIS y Apache Web Server se ve afectado por un desbordamiento de búfer basado en pila que puede ocurrir cuando se manipulan determinadas cookies web maliciosas que tienen formatos no válidos. El atacante podría explotar esta vulnerabilidad para cerrar de manera inesperada el agente de autenticación y provocar una situación de denegación de servicio (DoS).
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-12-06 CVE Reserved
- 2018-03-28 CVE Published
- 2024-02-07 EPSS Updated
- 2024-09-17 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-787: Out-of-bounds Write
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
http://seclists.org/fulldisclosure/2018/Mar/60 | Mailing List | |
http://www.securitytracker.com/id/1040577 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Rsa Search vendor "Rsa" | Authentication Agent For Web Search vendor "Rsa" for product "Authentication Agent For Web" | <= 8.0.1 Search vendor "Rsa" for product "Authentication Agent For Web" and version " <= 8.0.1" | apache_web_server |
Affected
| ||||||
Rsa Search vendor "Rsa" | Authentication Agent For Web Search vendor "Rsa" for product "Authentication Agent For Web" | <= 8.0.1 Search vendor "Rsa" for product "Authentication Agent For Web" and version " <= 8.0.1" | iis |
Affected
|