Lucene search

K
ibmIBM33F3C0F8EBFDCD4BB099B8E9554DA8CD0E49E6ACD2C36563575A8913389A1240
HistoryMar 06, 2020 - 4:46 p.m.

Security Bulletin: A vulnerability in Samba affects IBM Spectrum Scale SMB protocol access method ( CVE-2019-14907)

2020-03-0616:46:49
www.ibm.com
10

0.006 Low

EPSS

Percentile

78.5%

Summary

A Samba vulnerability affects IBM Spectrum Scale SMB protocol access method that could cause denial of service. A fix for this vulnerability is available.

Vulnerability Details

CVEID:CVE-2019-14907
**DESCRIPTION:**Samba is vulnerable to a denial of service, caused by an error after a failed character conversion at log level 3 or above. By sending a specially crafted string during the NTLMSSP authentication exchange, an attacker could exploit this vulnerability to cause a long-lived process to terminate.
CVSS Base score: 6.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/174912 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Spectrum Scale All

Remediation/Fixes

For IBM Spectrum Scale V5.0.0.0 through 5.0.4.2, apply V5.0.4.3 available from FixCentral at:

https://www.ibm.com/support/fixcentral/swg/selectFixes?parent=Software%20defined%20storage&product=ibm/StorageSoftware/IBM+Spectrum+Scale&release=5.0.4&platform=All&function=all

For IBM Spectrum Scale V4.2.0.0 through V4.2.3.19, apply V4.2.3.20 available from FixCentral at:
https://www.ibm.com/support/fixcentral/swg/selectFixes?parent=Software%20defined%20storage&product=ibm/StorageSoftware/IBM+Spectrum+Scale&release=4.2.3&platform=All&function=all

If you cannot apply the latest level of service, contact IBM Service for an efix:

- For IBM Spectrum Scale V5.0.0.0 through V5.0.4.2, reference APAR IJ23359

- For IBM Spectrum Scale V4.2.0.0 through V4.2.3.19, reference APAR IJ23358

Workarounds and Mitigations

None