Dec 23, 2017 10:00 am EST
Share this post:
There is a vulnerability in Mozilla NSS to which the IBM® FlashSystem™ V840 is susceptible. An exploit of this vulnerability (CVE-2016-9074) could make the system susceptible to timing side-channel attacks which could be leveraged to allow launch of further attacks on the system
CVE(s): CVE-2016-9074
Affected product(s) and affected version(s):
Storage Node machine type and models (MTMs) affected: 9840-AE1 and 9843-AE1
Controller Node MTMs affected: 9846-AC0, 9848-AC0, 9846-AC1, and 9848-AC1
Supported storage node code versions which are affected
· VRMFs prior to 1.3.0.7
· VRMFs prior to 1.4.5.0
Supported controller node code versions which are affected
· VRMFs prior to 7.5.0.10 or 7.5.1.5
· VRMFs prior to 7.6.1.7
· VRMFs prior to 7.7.1.6
· VRMFs prior to 7.8.0.2 or 7.8.1.0
Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2poAn22
X-Force Database: http://ift.tt/2ryTPpv
from IBM Product Security Incident Response Team http://ift.tt/2plM2yo
No comments:
Post a Comment
Note: Only a member of this blog may post a comment.