English
The Internet threat alert status is currently normal. At present, no major epidemics or other serious incidents have been recorded by Kaspersky Lab’s monitoring service. Internet threat level: 1

RSA BSAFE Micro Edition Suite SSL/TLS Initialization Vector Selection Weakness


Secunia ID

SA50605

CVE-ID

CVE-2011-3389

Release Date

12 Sep 2012

Criticality

Not Critical

Solution Status

Vendor Patch

Software

RSA BSAFE

Where

From remote

Impact
Exposure of sensitive information

Vulnerabilities where documents or credentials are leaked or can be revealed either locally or from remote.

Hijacking

This covers vulnerabilities where a user session or a communication channel can be taken over by other users or remote attackers.

Description

EMC has acknowledged a weakness in RSA BSAFE, which can be exploited by malicious people to disclose potentially sensitive information and hijack a user's session.

A design error exists within the implementation of SSL 3.0 and TLS 1.0 protocols.

For more information:
SA46168

The weakness is reported in RSA BSAFE Micro Edition Suite versions prior to 4.0.

Solution

Update to RSA BSAFE Micro Edition Suite version 4.0.

Original Advisory

http://archives.neohapsis.com/archives/bugtraq/2012-09/att-0040/ESA-2012-032.txt