Lucene search

K
ibmIBM18C4D8482F163ADD89464F41AF61364138B76189E783ABBB92E6C26069BF952D
HistoryDec 18, 2019 - 2:26 p.m.

Security Bulletin: IBM i is affected by networking BIND vulnerabilities CVE-2015-5477 and CVE-2015-4620.

2019-12-1814:26:38
www.ibm.com
14

EPSS

0.972

Percentile

99.8%

Summary

BM i is affected by several ISC BIND vulnerabilities.

Vulnerability Details

CVEID: CVE-2015-5477 DESCRIPTION: ISC BIND is vulnerable to a denial of service, caused by an error in the handling of TKEY queries. By sending specially-crafted packets, a remote attacker could exploit this vulnerability to cause a REQUIRE assertion failure.
CVSS Base Score: 7.5
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/105120 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector:(AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

CVEID: CVE-2015-4620 DESCRIPTION: ISC BIND is vulnerable to a denial of service, caused by an error during DNSSEC validation by a recursive resolver. By sending specially-crafted zone data, a remote attacker could exploit this vulnerability to cause the recursive resolver to crash.
CVSS Base Score: 7.8
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/104434 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:C)

Affected Products and Versions

Releases 6.1, 7.1 and 7.2 of IBM i are affected.

Remediation/Fixes

The issue can be fixed by applying a PTF to the IBM i Operating System.

Releases 6.1, 7.1 and 7.2 of IBM i are supported and will be fixed.

Release 6.1 – SI57657 Release 7.1 – SI57654 Release 7.2 – SI57655

_Important note: _IBM recommends that all users running unsupported versions of affected products upgrade to supported and fixed version of affected products.

Workarounds and Mitigations

None known