Lucene search

K
ibmIBM6E75651EFD9E7A67FCAF2DA9D58C7BAEA179763B2AB9EAD957013233B763994A
HistoryJun 17, 2018 - 5:13 a.m.

Security Bulletin: Rational Systems Tester is affected by Libxml2 vulnerability (CVE-2015-8710)

2018-06-1705:13:39
www.ibm.com
9

0.009 Low

EPSS

Percentile

82.7%

Summary

Denial-Of-service vulnerability has been discovered in Libxml2 that was reported on Dec 31, 2015

Vulnerability Details

CVE-ID: CVE-2015-8710
Description: Libxml2 is vulnerable to a denial of service, caused by an out-of-bounds memory access when parsing an unclosed HTML comment. By using the “”<!–“” HTML comment without close, a remote attacker could exploit this vulnerability to trigger an out-of-bounds read and cause the system to crash.
CVSS Base Score: 5.3
CVSS Temporal Score: <https://exchange.xforce.ibmcloud.com/vulnerabilities/110076&gt; for more information
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)

Affected Products and Versions

3.3, 3.3.0.1, 3.3.0.2, 3.3.0.3, 3.3.0.4, 3.3.0.5, 3.3.0.6, 3.3.0.7

Remediation/Fixes

Upgrade to Rational Systems Tester Interim Fix 4 for 3.3.0.7.
Rational Systems Tester (3.3.0.7.iFix4, Windows)
Rational Systems Tester (3.3.0.7.iFix4, Linux)

Workarounds and Mitigations

None

0.009 Low

EPSS

Percentile

82.7%