OpenSSL vulnerabilities were disclosed on March 27 2018 by the OpenSSL Project. OpenSSL is used by IBM Rational ClearCase. IBM Rational ClearCase has addressed the applicable CVE.
CVEID: CVE-2018-0739 DESCRIPTION: OpenSSL is vulnerable to a denial of service. By sending specially crafted ASN.1 data with a recursive definition, a remote attacker could exploit this vulnerability to consume excessive stack memory.
CVSS Base Score: 5.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/140847 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
IBM Rational ClearCase versions:
Version
|
Status
—|—
9.0.1 through 9.0.1.3
|
Affected
9.0 through 9.0.0.6
|
Affected
8.0.1 through 8.0.1.17
|
Affected
8.0 through 8.0.0.21
|
Affected
Not all deployments of Rational ClearCase use OpenSSL in a way that is affected by these vulnerabilities.
You are vulnerable if your use of Rational ClearCase includes any of these configurations:
Apply a fix pack as listed in the table below. The fix pack includes OpenSSL 1.0.2o.
Affected Versions
|
Applying the fix
—|—
9.0.1 through 9.0.1.3
9.0 through 9.0.0.6
| Install Rational ClearCase Fix Pack 4 (9.0.1.4) for 9.0.1
8.0.1 through 8.0.1.17
8.0 through 8.0.0.21
| Install Rational ClearCase Fix Pack 18 (8.0.1.18) for 8.0.1
For 7.0.x, 7.1.x, 8.0.x and earlier releases, IBM recommends upgrading to a fixed, supported version/release/platform of the product.
None.