Home→Descriptions→SA50601
| Secunia ID | |
| CVE-ID | |
| Release Date |
12 Sep 2012 |
| Criticality | |
| Solution Status |
Vendor Patch |
| Software |
RSA BSAFE |
| Where | |
| Impact |
System accessThis covers vulnerabilities where malicious people are able to gain system access and execute arbitrary code with the privileges of a local user. Exposure of sensitive informationVulnerabilities where documents or credentials are leaked or can be revealed either locally or from remote. HijackingThis covers vulnerabilities where a user session or a communication channel can be taken over by other users or remote attackers. |
| Description |
EMC has acknowledged a weakness and a vulnerability in RSA BSAFE, which can be exploited by malicious people to disclose sensitive information, hijack a user's session, and potentially compromise an application using the library. For more information: The weakness and the vulnerability are reported in RSA BSAFE SSL-C versions prior to 2.8.6. |
| Solution |
Update to RSA BSAFE SSL-C version 2.8.6. |
| Original Advisory |
http://archives.neohapsis.com/archives/bugtraq/2012-09/att-0046/ESA-2012-029.txt |