EMC RSA BSAFE Toolkits和RSA Data Protection Manager内存破坏漏洞

admin 2023-12-07 00:33:04 Ali_nvd 来源:ZONE.CI 全球网 0 阅读模式
EMC RSA BSAFE Toolkits和RSA Data Protection Manager内存破坏漏洞

CVE编号

CVE-2013-6078

利用情况

暂无

补丁情况

N/A

披露时间

2014-06-18
漏洞描述
The default configuration of EMC RSA BSAFE Toolkits and RSA Data Protection Manager (DPM) 20130918 uses the Dual Elliptic Curve Deterministic Random Bit Generation (Dual_EC_DRBG) algorithm, which makes it easier for context-dependent attackers to defeat cryptographic protection mechanisms by leveraging unspecified "security concerns," aka the ESA-2013-068 issue. NOTE: this issue has been SPLIT from CVE-2007-6755 because the vendor announcement did not state a specific technical rationale for a change in the algorithm; thus, CVE cannot reach a conclusion that a CVE-2007-6755 concern was the reason, or one of the reasons, for this change.As with CVE-2007-6755 this vulnerability has been scored with the assumption the relationship between P and Q is known to the attacker. Please see CVE-2007-6755 [link: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2007-6755] more information.
解决建议
建议您更新当前系统或软件至最新版,完成漏洞的修复。
参考链接
http://arstechnica.com/security/2013/09/stop-using-nsa-influence-code-in-our-...
http://blog.cryptographyengineering.com/2013/09/rsa-warns-developers-against-...
http://stream.wsj.com/story/latest-headlines/SS-2-63399/SS-2-332655/
http://threatpost.com/in-wake-of-latest-crypto-revelations-everything-is-suspect
受影响软件情况
# 类型 厂商 产品 版本 影响面
1
运行在以下环境
应用 emc rsa_bsafe_toolkits - -
运行在以下环境
应用 emc rsa_data_protection_manager 20130918 -
CVSS3评分 5.8
  • 攻击路径 网络
  • 攻击复杂度 N/A
  • 权限要求 无
  • 影响范围 N/A
  • 用户交互 无
  • 可用性 无
  • 保密性 部分地
  • 完整性 部分地
AV:N/AC:M/Au:N/C:P/I:P/A:N
CWE-ID 漏洞类型
- avd.aliyun.com
weinxin
版权声明
本站原创文章转载请注明文章出处及链接,谢谢合作!
N/A Ali_nvd

N/A

N/ACVE编号 CVE-2024-9120利用情况 暂无补丁情况 N/A披露时间 2024-09-23漏洞描述Use after free in Dawn
评论:0   参与:  0