ID

VAR-E-200705-0522


CVE

cve_id:CVE-2006-3894

Trust: 0.3

sources: BID: 24104

TITLE

RSA BSAFE Library Remote ASN.1 Denial of Service Vulnerability

Trust: 0.3

sources: BID: 24104

DESCRIPTION

The RSA BSAFE library is prone to a denial-of-service vulnerability because it fails to properly handle malformed ASN.1 data.
Exploiting this vulnerability allows attackers to crash applications that use the affected library. The specific impact of this vulnerability depends on the nature of the applications. Local and remote attacks may be possible. Depending on the nature of vulnerable applications, attackers may be able to exploit this issue without authentication.
These versions are vulnerable:
RSA BSAFE Crypto-C prior to 6.3.1
Cert-C prior to 2.8
The vendor tracks this issue by RSA Bug ID 46337.
Cisco tracks this issue as Bug IDs:
Cisco IOS: CSCsd85587
Cisco IOS XR: CSCsg41084
Cisco PIX and ASA Security Appliances: CSCse91999
Cisco Firewall Services Module (FWSM): CSCsi97695
Cisco Unified CallManager: CSCsg44348

Trust: 0.3

sources: BID: 24104

AFFECTED PRODUCTS

vendor:ciscomodel:unified callmanagerscope:eqversion:5.0

Trust: 0.9

vendor:ciscomodel:firewall services modulescope:eqversion:2.3(4.12)

Trust: 0.6

vendor:rsamodel:bsafe crypto-cscope:eqversion:0

Trust: 0.3

vendor:rsamodel:bsafe cert-cscope:eqversion:0

Trust: 0.3

vendor:novellmodel:international cryptographic infostructurescope:eqversion:2.6.1

Trust: 0.3

vendor:ciscomodel:unified communications managerscope:eqversion:5.1(1)

Trust: 0.3

vendor:ciscomodel:unified callmanager 5.0 su1scope: - version: -

Trust: 0.3

vendor:ciscomodel:unified callmanagerscope:eqversion:5.0(4)

Trust: 0.3

vendor:ciscomodel:unified callmanager 5.0scope: - version: -

Trust: 0.3

vendor:ciscomodel:unified callmanagerscope:eqversion:5.0(3)

Trust: 0.3

vendor:ciscomodel:unified callmanagerscope:eqversion:5.0(2)

Trust: 0.3

vendor:ciscomodel:unified callmanagerscope:eqversion:5.0(1)

Trust: 0.3

vendor:ciscomodel:unified callmanager 4.2 sr1scope: - version: -

Trust: 0.3

vendor:ciscomodel:unified callmanagerscope:eqversion:4.2

Trust: 0.3

vendor:ciscomodel:unified callmanager 4.1 sr4scope: - version: -

Trust: 0.3

vendor:ciscomodel:unified callmanagerscope:eqversion:4.1

Trust: 0.3

vendor:ciscomodel:unified callmanagerscope:eqversion:4.0

Trust: 0.3

vendor:ciscomodel:pix/asascope:eqversion:7.0.4.3

Trust: 0.3

vendor:ciscomodel:pix/asascope:eqversion:7.0.4

Trust: 0.3

vendor:ciscomodel:pix/asascope:eqversion:7.0.1.4

Trust: 0.3

vendor:ciscomodel:pix/asascope:eqversion:7.0

Trust: 0.3

vendor:ciscomodel:pix/asascope:eqversion:7.2(1)

Trust: 0.3

vendor:ciscomodel:pix/asascope:eqversion:7.1(2)

Trust: 0.3

vendor:ciscomodel:pix/asascope:eqversion:7.0(5.2)

Trust: 0.3

vendor:ciscomodel:pix/asascope:eqversion:7.0(5)

Trust: 0.3

vendor:ciscomodel:ios xrscope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 12.4xpscope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 12.4xjscope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 12.4xescope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 12.4xdscope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 12.4xcscope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 12.4xbscope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 12.4xascope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 12.4tscope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 12.4swscope: - version: -

Trust: 0.3

vendor:ciscomodel:iosscope:eqversion:12.4

Trust: 0.3

vendor:ciscomodel:ios 12.3yzscope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 12.3yxscope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 12.3yuscope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 12.3ytscope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 12.3ysscope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 12.3yqscope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 12.3ykscope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 12.3yiscope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 12.3yhscope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 12.3ygscope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 12.3yfscope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 12.3ydscope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 12.3yascope: - version: -

Trust: 0.3

vendor:ciscomodel:iosscope:eqversion:12.3xx

Trust: 0.3

vendor:ciscomodel:ios 12.3xwscope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 12.3xuscope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 12.3xsscope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 12.3xrscope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 12.3xqscope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 12.3xkscope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 12.3xjscope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 12.3xiscope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 12.3xhscope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 12.3xgscope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 12.3xfscope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 12.3xescope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 12.3xdscope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 12.3xcscope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 12.3xbscope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 12.3xascope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 12.3tpcscope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 12.3tscope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 12.3jxscope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 12.3jlscope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 12.3jkscope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 12.3jeascope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 12.3jascope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 12.3bcscope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 12.3bscope: - version: -

Trust: 0.3

vendor:ciscomodel:iosscope:eqversion:12.3

Trust: 0.3

vendor:ciscomodel:ios 12.2zuscope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 12.2zlscope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 12.2zjscope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 12.2zhscope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 12.2zgscope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 12.2zfscope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 12.2zescope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 12.2zdscope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 12.2yvscope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 12.2yuscope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 12.2xrscope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 12.2tscope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 12.2sxfscope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 12.2sxescope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 12.2sxdscope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 12.2srbscope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 12.2srascope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 12.2sgascope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 12.2sgscope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 12.2segscope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 12.2sefscope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 12.2seescope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 12.2sedscope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 12.2secscope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 12.2sebscope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 12.2seascope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 12.2sescope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 12.2sbscope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 12.2jkscope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 12.2jascope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 12.2ixcscope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 12.2ixbscope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 12.2ixascope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 12.2fzscope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 12.2fyscope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 12.2fxscope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 12.2ezscope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 12.2eyscope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 12.2exscope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 12.2ewascope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 12.2ewscope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 12.2czscope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 12.2cxscope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 12.2bzscope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 12.2bcscope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 12.2bscope: - version: -

Trust: 0.3

vendor:ciscomodel:ios zwscope:eqversion:12.2

Trust: 0.3

vendor:ciscomodel:firewall services modulescope:eqversion:3.1(4)

Trust: 0.3

vendor:ciscomodel:firewall services modulescope:eqversion:3.1(3.24)

Trust: 0.3

vendor:ciscomodel:firewall services modulescope:eqversion:3.1(1.9)

Trust: 0.3

vendor:ciscomodel:firewall services modulescope:eqversion:3.1(1.7)

Trust: 0.3

vendor:ciscomodel:firewall services modulescope:eqversion:3.1(3.3)

Trust: 0.3

vendor:ciscomodel:firewall services modulescope:eqversion:3.1(3.2)

Trust: 0.3

vendor:ciscomodel:firewall services modulescope:eqversion:3.1(3.18)

Trust: 0.3

vendor:ciscomodel:firewall services modulescope:eqversion:3.1(3.11)

Trust: 0.3

vendor:ciscomodel:firewall services modulescope:eqversion:3.1(3.1)

Trust: 0.3

vendor:ciscomodel:firewall services modulescope:eqversion:3.1

Trust: 0.3

vendor:ciscomodel:firewall services modulescope:eqversion:2.3(4.7)

Trust: 0.3

vendor:ciscomodel:firewall services modulescope:eqversion:2.3(4)

Trust: 0.3

vendor:ciscomodel:firewall services modulescope:eqversion:2.3

Trust: 0.3

vendor:rsamodel:bsafe crypto-cscope:neversion:6.3.1

Trust: 0.3

vendor:rsamodel:bsafe cert-cscope:neversion:2.8

Trust: 0.3

vendor:novellmodel:international cryptographic infrastructurescope:neversion:2.7.2

Trust: 0.3

vendor:ciscomodel:unified communications managerscope:neversion:5.1(2)

Trust: 0.3

vendor:ciscomodel:unified communications manager 4.3 sr.1scope:neversion: -

Trust: 0.3

vendor:ciscomodel:unified communications manager 4.2 sr2scope:neversion: -

Trust: 0.3

vendor:ciscomodel:unified callmanager 4.1 sr5scope:neversion: -

Trust: 0.3

vendor:ciscomodel:pix/asascope:neversion:8.0

Trust: 0.3

vendor:ciscomodel:pix/asascope:neversion:7.2(2)

Trust: 0.3

vendor:ciscomodel:pix/asascope:neversion:7.2(1.22)

Trust: 0.3

vendor:ciscomodel:pix/asascope:neversion:7.1(2.27)

Trust: 0.3

vendor:ciscomodel:pix/asascope:neversion:7.0(6.7)

Trust: 0.3

vendor:ciscomodel:pix/asascope:neversion:6.0

Trust: 0.3

vendor:ciscomodel:ios xrscope:neversion:3.4.1

Trust: 0.3

vendor:ciscomodel:ios xrscope:neversion:3.4

Trust: 0.3

vendor:ciscomodel:ios xrscope:neversion:3.3.3

Trust: 0.3

vendor:ciscomodel:ios xrscope:neversion:3.3.2

Trust: 0.3

vendor:ciscomodel:ios xrscope:neversion:3.3.1

Trust: 0.3

vendor:ciscomodel:ios xrscope:neversion:3.3

Trust: 0.3

vendor:ciscomodel:ios xrscope:neversion:3.2.6

Trust: 0.3

vendor:ciscomodel:ios xrscope:neversion:3.2.4

Trust: 0.3

vendor:ciscomodel:ios xrscope:neversion:3.2.3

Trust: 0.3

vendor:ciscomodel:ios 12.4 t3scope:neversion: -

Trust: 0.3

vendor:ciscomodel:ios 12.4scope:neversion: -

Trust: 0.3

vendor:ciscomodel:ios 12.4 t7scope:neversion: -

Trust: 0.3

vendor:ciscomodel:ios 12.4 xd6scope:neversion: -

Trust: 0.3

vendor:ciscomodel:ios 12.4 xc6scope:neversion: -

Trust: 0.3

vendor:ciscomodel:ios 12.4 xj2scope:neversion: -

Trust: 0.3

vendor:ciscomodel:ios 12.4 t1scope:neversion: -

Trust: 0.3

vendor:ciscomodel:ios 12.4 sw1scope:neversion: -

Trust: 0.3

vendor:ciscomodel:iosscope:neversion:12.4(10)

Trust: 0.3

vendor:ciscomodel:iosscope:neversion:12.3(22)

Trust: 0.3

vendor:ciscomodel:ios 12.3 jl1scope:neversion: -

Trust: 0.3

vendor:ciscomodel:ios 12.3 bc6scope:neversion: -

Trust: 0.3

vendor:ciscomodel:ios 12.3 yx7scope:neversion: -

Trust: 0.3

vendor:ciscomodel:ios 12.2 sgscope:neversion: -

Trust: 0.3

vendor:ciscomodel:ios 12.2 se2scope:neversion: -

Trust: 0.3

vendor:ciscomodel:ios 12.2 srbscope:neversion: -

Trust: 0.3

vendor:ciscomodel:ios 12.2 sra2scope:neversion: -

Trust: 0.3

vendor:ciscomodel:ios 12.2 sga1scope:neversion: -

Trust: 0.3

vendor:ciscomodel:ios 12.2 sb3scope:neversion: -

Trust: 0.3

vendor:ciscomodel:ios 12.2 see3scope:neversion: -

Trust: 0.3

vendor:ciscomodel:ios 12.2 ewa9scope:neversion: -

Trust: 0.3

vendor:ciscomodel:ios 12.2 sxf8scope:neversion: -

Trust: 0.3

vendor:ciscomodel:firewall services modulescope:neversion:3.1(6)

Trust: 0.3

vendor:ciscomodel:firewall services modulescope:neversion:2.3(5)

Trust: 0.3

sources: BID: 24104

EXPLOIT

To exploit this issue, attackers use readily available network utilities for creating and injecting packets.

Trust: 0.3

sources: BID: 24104

PRICE

Free

Trust: 0.3

sources: BID: 24104

TYPE

Failure to Handle Exceptional Conditions

Trust: 0.3

sources: BID: 24104

CREDITS

The original discoverer of this issue is unknown. It was disclosed in the referenced US-CERT advisory.

Trust: 0.3

sources: BID: 24104

EXTERNAL IDS

db:CERT/CCid:VU#754281

Trust: 0.3

db:NVDid:CVE-2006-3894

Trust: 0.3

db:BIDid:24104

Trust: 0.3

sources: BID: 24104

REFERENCES

url:http://www.cisco.com/warp/public/707/cisco-sa-20070522-crypto.shtml

Trust: 0.3

url:http://www.rsa.com/

Trust: 0.3

url:http://tools.cisco.com/security/center/content/ciscosecurityadvisory/cisco-sa-20151130-csr

Trust: 0.3

url:http://www.kb.cert.org/vuls/id/754281

Trust: 0.3

url:http://www116.nortelnetworks.com/pub/repository/clarify/document/2007/21/022317-01.pdf

Trust: 0.3

url:https://secure-support.novell.com/kanisaplatform/publishing/97/3590033_f.sal_public.html

Trust: 0.3

url:http://www.rsa.com/node.aspx?id=1204

Trust: 0.3

sources: BID: 24104

SOURCES

db:BIDid:24104

LAST UPDATE DATE

2022-07-27T09:36:40.627000+00:00


SOURCES UPDATE DATE

db:BIDid:24104date:2007-06-29T18:58:00

SOURCES RELEASE DATE

db:BIDid:24104date:2007-05-22T00:00:00