Lucene search

K
ibmIBM01D95B74237E71AF3B9E6B275E1090CD08126FB0C03CC0614B217638198EE9F1
HistorySep 24, 2018 - 8:15 a.m.

Security Bulletin: OpenSSH vulnerability affects IBM Spectrum Protect Plus (CVE-2017-15906)

2018-09-2408:15:01
www.ibm.com
19

0.007 Low

EPSS

Percentile

79.7%

Summary

OpenSSH is vulnerable to a denial of service vulnerability which affects IBM Spectrum Protect Plus.

Vulnerability Details

CVEID: CVE-2017-15906 DESCRIPTION: OpenSSH is vulnerable to a denial of service, caused by an error in the process_open() function when in read-only mode. A remote authenticated attacker could exploit this vulnerability to create zero-length files and cause a denial of service.
CVSS Base Score: 6.5
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/133128&gt; for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)

Affected Products and Versions

IBM Spectrum Protect Plus 10.1.0 and 10.1.1.

Remediation/Fixes

IBM Spectrum Protect Plus Release

| First Fixing
VRM Level
|Platform|Link to Fix / Fix Availability Target
—|—|—|—
10.1 | 10.1.2 | Linux |

<http://www.ibm.com/support/docview.wss?uid=swg24044949&gt;

.

Workarounds and Mitigations

None.