>> Cisco Products Crypto Library ASN.1 Objects Processing Denial of Service Vulnerability
Title : Cisco Products Crypto Library ASN.1 Objects Processing Denial of Service Vulnerability VUPEN ID : VUPEN/ADV-2007-1909 CVE ID : CVE-2006-3894
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-05-22
Technical Description
A vulnerability has been identified in various Cisco products, which could be exploited by remote attackers to cause a denial of service. This issue is caused by an error in the RSA BSAFE library when parsing malformed Abstract Syntax Notation One (ASN.1) objects, which could be exploited by attackers to crash a vulnerable device, creating a denial of service condition. For additional information, see : VUPEN/ADV-2007-1908