Lucene search

K
ibmIBM2C693F09B60ADC21713099A3B565FD7AF6CD46D32371984C82AD868E67FABB5D
HistoryApr 17, 2019 - 5:05 p.m.

Security Bulletin: IBM QRadar Network Packet Capture is vulnerable to publicly disclosed vulnerabilities from [All] Python (CVE-2018-1060, CVE-2018-1061)

2019-04-1717:05:01
www.ibm.com
16

EPSS

0.006

Percentile

79.2%

Summary

Python as used by IBM QRadar Network Packet Capture is vulnerable to a denial of service

Vulnerability Details

CVEID: CVE-2018-1060
**Description:**Python is vulnerable to a denial of service, caused by catastrophic backtracking in the pop3lib’s apop() method. A remote attacker could exploit this vulnerability to cause the application to crash.
**CVSS Base Score:**6.5
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/145116&gt; for the current score
**CVSS Environmental Score:***Undefined
**CVSS Vector:**CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

CVEID: CVE-2018-1061
**Description:**Python is vulnerable to a denial of service, caused by catastrophic backtracking in the difflib.IS_LINE_JUNK method. A remote attacker could exploit this vulnerability to cause the application to crash.
**CVSS Base Score:**6.5
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/145115&gt; for the current score
**CVSS Environmental Score:***Undefined
**CVSS Vector:**CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Affected Products and Versions

IBM Security QRadar Packet Capture 7.2.0 - 7.2.8 Patch 2

IBM Security QRadar Packet Capture 7.3.0 - 7.3.1 Patch 2

Remediation/Fixes

QRadar Network Packet Capture 7.2.8 Patch 3

QRadar Network Packet Capture 7.3.2 GA

Workarounds and Mitigations

None