Lucene search

K
ibmIBM5F1BA13C55B19C10D869D04226DD07845A8F18C00B2E041E0C4432AE7FBB16EB
HistoryJun 18, 2018 - 1:41 a.m.

Security Bulletin: A vulnerability in DHCP affects PowerKVM

2018-06-1801:41:33
www.ibm.com
16

0.144 Low

EPSS

Percentile

95.8%

Summary

PowerKVM is affected by a vulnerability in DHCP. IBM has now addressed this vulnerability.

Vulnerability Details

CVEID: CVE-2017-3144**
DESCRIPTION:** ISC DHCP is vulnerable to a denial of service, caused by the failure to properly clean up closed OMAPI connections. A remote attacker could exploit this vulnerability to consume all available socket descriptors for the target DHCP service.
CVSS Base Score: 5.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/137696 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)

Affected Products and Versions

PowerKVM 3.1

Remediation/Fixes

Customers can update PowerKVM systems by using “yum update”.

Fix images are made available via Fix Central. For version 3.1, see https://ibm.biz/BdHggw. This issue is addressed starting with v3.1.0.2 update 13.

Workarounds and Mitigations

none

CPENameOperatorVersion
powerkvmeq3.1