Tuesday, November 26, 2019

Security Bulletin: Vulnerabilities in OpenSSL affect AIX (CVE-2019-1547, CVE-2019-1563)

Nov 26, 2019 7:00 pm EST

Categorized: Medium Severity

Share this post:

There are vulnerabilities in OpenSSL used by AIX.

Affected product(s) and affected version(s):

Affected Product(s) Version(s)
AIX 7.1
AIX 7.2
VIOS 2.2
VIOS 3.1

 

The following fileset levels are vulnerable:

        

key_fileset = osrcaix

 

Fileset Lower Level Upper Level Key
openssl.base 1.0.2.500 1.0.2.1801 key_w_fs
openssl.base 20.13.102.1000 20.16.102.1801 key_w_fs

 

Note:

        A. 0.9.8, 1.0.1 OpenSSL versions are out-of-support. Customers are advised to upgrade to currently supported OpenSSL 1.0.2 version.

 

        B. Latest level of OpenSSL fileset is available from the web download site:

  

To find out whether the affected filesets are installed on your systems, refer to the lslpp command found in the AIX user's guide.

 

Example:  lslpp -L | grep -i openssl.base

Refer to the following reference URLs for remediation and additional vulnerability details:  
Source Bulletin: https://www.ibm.com/support/pages/node/1116033



from IBM Product Security Incident Response Team https://ift.tt/2QThpfZ

No comments:

Post a Comment

Note: Only a member of this blog may post a comment.