Lucene search

K
ibmIBM81888C5B2AB508173E8A42F5BFE94831F0AC299F823257C974E685AD0574CB4F
HistoryFeb 25, 2022 - 1:06 p.m.

Security Bulletin: IBM Netezza for Cloud Pak for Data is vulnerable to arbitrary code execution (CVE-2021-44142).

2022-02-2513:06:29
www.ibm.com
30

0.18 Low

EPSS

Percentile

96.2%

Summary

Samba is included in IBM Netezza for Cloud Pak for Data. Samba is not actively used and have limited exposure to CVE-2021-44142. Vulnerability is fixed. Fix includes updated version of samba client. (samba-client-libs-4.10.16-18.el7_9.x86_64)

Vulnerability Details

CVEID:CVE-2021-44142
**DESCRIPTION:**Samba could allow a remote authenticated attacker to execute arbitrary code on the system, caused by an out-of-bounds heap read write in the VFS module vfs_fruit. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary code as root on the system.
CVSS Base score: 9.9
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/218420 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Netezza for Cloud Pak for Data 11.1.0.0 - 11.2.1.3

Remediation/Fixes

IBM Strongly recommends addressing vulnerability although samba is not used actively:

Product Version Remediation/First Fix
IBM Netezza for Cloud Pak for Data 11.2.1.4 Link To Fix Central

Workarounds and Mitigations

None