Vulnerabilities in GSKit affect IBM Spectrum Scale where: – a local attacker could obtain control of the Spectrum Scale daemon and to access and modify files in the Spectrum Scale file system, and possibly to obtain administrator privileges on the node (CVE-2018-1431) – OpenSSL could allow a remote attacker to obtain sensitive information, caused by a carry propagation flaw in the x86_64 Montgomery squaring function bn_sqrx8x_internal(). An attacker with online access to an unpatched system could exploit this vulnerability to obtain information about the private key (CVE-2017-3736) – OpenSSL could allow a remote attacker to obtain sensitive information, caused by a carry propagating bug in the x86_64 Montgomery squaring procedure. An attacker could exploit this vulnerability to obtain information about the private key (CVE-2017-3732) – OpenSSL is vulnerable to a denial of service, caused by a double-free error when parsing DSA private keys. An attacker could exploit this vulnerability to corrupt memory and cause a denial of service (CVE-2016-0705)
CVE(s): CVE-2018-1431, CVE-2017-3736, CVE-2017-3732, CVE-2016-0705
Affected product(s) and affected version(s):
IBM Spectrum Scale V5.0.0.0 thru V5.0.0.2
IBM Spectrum Scale V4.2.3.0 thru V4.2.3.8
IBM Spectrum Scale V4.2.2.0 thru V4.2.2.3
IBM Spectrum Scale V4.2.1.0 thru V4.2.1.2
IBM Spectrum Scale V4.2.0.0 thru V4.2.0.4
IBM Spectrum Scale V4.1.1.0 thru V4.1.1.19
IBM General Parallel File System V4.1.0.0 thru V4.1.0.8
Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://www-01.ibm.com/support/docview.wss?uid=ssg1S1012049
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/139240
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/134397
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/121313
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/111140
The post IBM Security Bulletin: Vulnerabilities in GSKit affect IBM Spectrum Scale (CVE-2018-1431, CVE-2017-3736, CVE-2017-3732, CVE-2016-0705 ) appeared first on IBM PSIRT Blog.
from IBM Product Security Incident Response Team https://ift.tt/2sOl2qL
No comments:
Post a Comment
Note: Only a member of this blog may post a comment.