Lucene search

K
ibmIBM366C73D8ADE9CAF3136A5CB4A2B8E754946816A45006CF3D92CD5DDB949E5777
HistoryOct 20, 2020 - 3:39 p.m.

Security Bulletin: Multiple vulnerabilities in GNU Binutils affect IBM Netezza Platform Software clients.

2020-10-2015:39:19
www.ibm.com
17

0.002 Low

EPSS

Percentile

61.1%

Summary

GNU Binutils is used by IBM Netezza Platform Software. IBM Netezza Platform Software has addressed the applicable CVEs.

Vulnerability Details

CVEID:CVE-2019-9070
**DESCRIPTION:**GNU Binutils is vulnerable to a heap-based buffer overflow, caused by a buffer over-read flaw in the d_expression_1 function in cp-demangle.c. By persuading a victim to open a specially-crafted file, a remote attacker could overflow a buffer and execute arbitrary code on the system.
CVSS Base score: 7.8
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/157912 for the current score.
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)

CVEID:CVE-2019-9071
**DESCRIPTION:**GNU Binutils is vulnerable to a stack-based buffer overflow, caused by a stack consumption flaw in the d_count_templates_scopes function in cp-demangle.c. By persuading a victim to open a specially-crafted file, a remote attacker could overflow a buffer and execute arbitrary code on the system.
CVSS Base score: 7.8
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/157913 for the current score.
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Netezza Platform Software 4.6.8-4.6.12.P5
IBM Netezza Platform Software 5.0.10-5.2.2.P5
IBM Netezza Platform Software 6.0.3-6.1.P2
IBM Netezza Platform Software 7.0-7.2.1.10

Remediation/Fixes

To resolve the reported CVEs on following platforms :
PureData System for Analytics N3001
PureData System for Analytics N200x

Update to the following IBM Netezza Platform Software Release :

Product VRMF Remediation/First Fix
IBM Netezza Platform Software 7.2.1.10-P1 Fix Central Link

Workarounds and Mitigations

None

0.002 Low

EPSS

Percentile

61.1%