Lucene search

K
ibmIBM9E63E9416444AA2DF1664209083F4A7A31363BE16B637E0BA27E1FF0733D991A
HistoryJun 21, 2021 - 8:26 p.m.

Security Bulletin: IBM Bootable Media Creator (BoMC) is affected by vulnerabilities in libexpat

2021-06-2120:26:43
www.ibm.com
22

0.582 Medium

EPSS

Percentile

97.7%

Summary

IBM Bootable Media Creator (BoMC) has addressed the following vulnerabilities.

Vulnerability Details

CVEID:CVE-2018-20843
**DESCRIPTION:**libexpat is vulnerable to a denial of service, caused by an error in the XML parser. By persuading a victim to open a specially-crafted file, a remote attacker could exploit this vulnerability to consume all available CPU resources.
CVSS Base score: 3.3
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/163073 for the current score.
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L)

CVEID:CVE-2019-15903
**DESCRIPTION:**libexpat is vulnerable to a denial of service, caused by a heap-based buffer over-read in XML_GetCurrentLineNumber. By using a specially-crafted XML input, a remote attacker could exploit this vulnerability to cause the application to crash.
CVSS Base score: 5.3
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/166560 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)

Affected Products and Versions

The fix is downloaded automatically by BoMC in the background and is not independently accessible on Fix Central.

Remediation/Fixes

The fix is downloaded automatically by BoMC in the background and is not independently accessible on Fix Central.

Workarounds and Mitigations

None