Lucene search

K
ibmIBM37C10C2D0E7D2BFB4BB1A32B884A646EE86AC573C6ABC320C9FB60A8F1A3ECB6
HistoryOct 13, 2022 - 9:28 p.m.

Security Bulletin: XL compilers on AIX are vulnerable to denial of service due to zlib and zlibNX (CVE-2018-25032)

2022-10-1321:28:45
www.ibm.com
15
security bulletin
aix
xl compilers
denial of service
zlib
zlibnx
cve-2018-25032

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.003

Percentile

68.4%

Summary

A vulnerability in zlib and zlibNX could allow a remote attacker to cause a denial of service (CVE-2018-25032). XL compilers on AIX use zlib and zlibNX as part of its data compression functions.

Vulnerability Details

Refer to the security bulletin(s) listed in the Remediation/Fixes section

Affected Products and Versions

Affected Product(s) Version(s)

Open XL C/C++/Fortran for AIX

| V17.1.1

XL C/C++/Fortran for AIX

| V16.1.0

Remediation/Fixes

XL compilers on AIX are making use of the AIX OS supplied zlib libraries. Please see <https://www.ibm.com/support/pages/node/6824891/&gt; for remediation/fixes.

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmaixMatch17.1.1
OR
ibmaixMatch16.1.0
OR
ibmaixMatch17.1.1
OR
ibmaixMatch16.1.0
VendorProductVersionCPE
ibmaix17.1.1cpe:2.3:o:ibm:aix:17.1.1:*:*:*:*:*:*:*
ibmaix16.1.0cpe:2.3:o:ibm:aix:16.1.0:*:*:*:*:*:*:*

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.003

Percentile

68.4%