Lucene search

K
ibmIBM4114A48154E931830AEA7EF1C25697D9D940E6F80AED3819E0A20B2AE16DD3D9
HistoryJun 16, 2018 - 1:43 p.m.

Security Bulletin: Vulnerability in libxml2 affects IBM Streams (CVE-2016-3705)

2018-06-1613:43:11
www.ibm.com
17

EPSS

0.011

Percentile

84.4%

Summary

There is a vulnerability in libxml2 that is used by IBM Streams. IBM Streams has addressed this vulnerability.

Vulnerability Details

CVEID: CVE-2016-3705**
DESCRIPTION:** libxml2 is vulnerable to a stack-based buffer overflow, caused by an out-of-bounds read of xmlParserEntityCheck() and xmlParseAttValueComplex() functions in parser.c. By persuading a victim to open a specially crafted XML file, a remote attacker could overflow a buffer and execute arbitrary code on the system or cause the application to crash.
CVSS Base Score: 6.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/112885 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L)

Affected Products and Versions

    • IBM Streams Version 4.1.1.1 and earlier
  • IBM InfoSphere Streams Version 4.0.1.2 and earlier
  • IBM InfoSphere Streams Version 3.2.1.5 and earlier
  • IBM InfoSphere Streams Version 3.1.0.7 and earlier
  • IBM InfoSphere Streams Version 3.0.0.5 and earlier
  • IBM InfoSphere Streams Version 2.0.0.4 and earlier
  • IBM InfoSphere Streams Version 1.2.1.0

Remediation/Fixes

NOTE: Fix Packs are available on IBM Fix Central.

* **Version 4.1.1:**
  * Apply [4.1.1 Fix Pack 2 (4.1.1.2) or higher.](<https://www-945.ibm.com/support/fixcentral/swg/selectFixes?parent=ibm~Information%2BManagement&product=ibm/Information+Management/InfoSphere+Streams&release=4.1.1.0&platform=All&function=all>)
* **Version 4.0.1:**
  * Apply [4.0.1 Fix Pack 3 (4.0.1.3) or higher.](<https://www-945.ibm.com/support/fixcentral/swg/selectFixes?parent=ibm~Information%2BManagement&product=ibm/Information+Management/InfoSphere+Streams&release=4.0.1.0&platform=All&function=all>)
* **Version 3.2.1:**
  * Apply [3.2.1 Fix Pack 6 (3.2.1.6) or higher.](<https://www-945.ibm.com/support/fixcentral/swg/selectFixes?parent=ibm~Information%2BManagement&product=ibm/Information+Management/InfoSphere+Streams&release=3.2.1.0&platform=All&function=all>)
* **Version 3.1.0:**
  * Contact IBM Technical Support.
* **Version 3.0.0:**
  * Contact IBM Technical Support.
* **Versions 1.2 and 2.0:**
  * For version 1.x and 2.x, IBM recommends upgrading to a fixed, supported version/release/platform of the product. Customers who cannot upgrade and need to secure their installation should open a PMR with IBM Technical Support and request assistance securing their InfoSphere Streams system against the vulnerabilities identified in this Security Bulletin. 

Workarounds and Mitigations

None