Lucene search

K
ibmIBM3B7BADE1A849CE84A89804197B46A88E2CC7CDB9D5BCDAD1B99A5F1B61320366
HistoryJul 25, 2018 - 2:27 p.m.

Security Bulletin: IBM QRadar Network Security is affected by a GNU Compiler Collection (GCC) vulnerability

2018-07-2514:27:45
www.ibm.com
23

0.002 Low

EPSS

Percentile

52.5%

Summary

IBM QRadar Network Security has addressed the following vulnerability.

Vulnerability Details

CVEID:CVE-2017-11671
**DESCRIPTION:*GNU Compiler Collection (GCC) could provide weaker than expected security, caused by a flaw in the ix86_expand_builtin function in i386.c. A remote attacker could exploit this vulnerability to cause less randomness in random number generation.
CVSS Base Score: 5.3
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/129513&gt; for the current score
CVSS Environmental Score
: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)

Affected Products and Versions

IBM QRadar Network Security 5.4.0

Remediation/Fixes

Product

|

VRMF

|

Remediation/First Fix

—|—|—

IBM QRadar Network Security

| 5.4.0 |

Install Firmware 5.4.0.5 from the Available Updates page of the Local Management Interface, or by performing a One Time Scheduled Installation from SiteProtector.

Or

Download Firmware 5.4.0.5 from IBM Security License Key and Download Center and upload and install via the Available Updates page of the Local Management Interface.

Workarounds and Mitigations

None

CPENameOperatorVersion
ibm qradar network securityeq5.4.0

0.002 Low

EPSS

Percentile

52.5%