### [CVE-2018-11058](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-11058) ![](https://img.shields.io/static/v1?label=Product&message=BSAFE%20%20Crypto-C%20Micro%20Edition&color=blue) ![](https://img.shields.io/static/v1?label=Product&message=BSAFE%20Micro%20Edition%20Suite&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Vulnerability&message=Buffer%20Over-Read%20vulnerability&color=brighgreen) ### Description RSA BSAFE Micro Edition Suite, versions prior to 4.0.11 (in 4.0.x) and prior to 4.1.6 (in 4.1.x), and RSA BSAFE Crypto-C Micro Edition, version prior to 4.0.5.3 (in 4.0.x) contain a Buffer Over-Read vulnerability when parsing ASN.1 data. A remote attacker could use maliciously constructed ASN.1 data that would result in such issue. ### POC #### Reference - https://www.oracle.com/security-alerts/cpuapr2020.html - https://www.oracle.com/security-alerts/cpujan2020.html - https://www.oracle.com/security-alerts/cpujul2020.html - https://www.oracle.com/security-alerts/cpuoct2020.html #### Github No PoCs found on GitHub currently.