CVE-2018-1232
Description
RSA Authentication Agent version 8.0.1 and earlier for Web for both IIS and Apache Web Server are impacted by a stack-based buffer overflow which may occur when handling certain malicious web cookies that have invalid formats. The attacker could exploit this vulnerability to crash the authentication agent and cause a denial-of-service situation.
CWE
- (none)
Affected
- Dell EMC / RSA Authentication Agent for Web for IIS, RSA Authentication Agent for Web for Apache Web Server — v=version 8.0.1 and earlier [affected]
CVSS
- (none)
References
- http://seclists.org/fulldisclosure/2018/Mar/60 mailing-list, x_refsource_FULLDISC
- http://www.securitytracker.com/id/1040577 vdb-entry, x_refsource_SECTRACK
Source
cvelistV5-main/cves/2018/1xxx/CVE-2018-1232.json