Lucene search

K
ibmIBMA58920C51844C3EB0D56077CF21717B6E79B3F6C399A997734F99352AA86099F
HistoryJun 18, 2018 - 1:29 a.m.

Security Bulletin: Vulnerability in Mozilla NSS affects PowerKVM (CVE-2015-2730)

2018-06-1801:29:25
www.ibm.com
24

EPSS

0.003

Percentile

70.7%

Summary

PowerKVM is affected by a vulnerability in Mozilla NSS (CVE-2015-2730). This vulnerability is now fixed. Note that this primarily affects Mozilla Firefox, which does not ship with PowerKVM.

Vulnerability Details

CVEID: CVE-2015-2730**
DESCRIPTION:** Mozilla Firefox could allow a remote attacker to bypass security restrictions, caused by the failure to properly handle certain exceptional cases by the Elliptical Curve Cryptography (ECC) multiplication for Elliptic Curve Digital Signature Algorithm (ECDSA) signature validation in Network Security Services (NSS). By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to forge signatures.
CVSS Base Score: 4.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/#/vulnerabilities/104386 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N)

Note that this primarily affects Mozilla Firefox, which does not ship with PowerKVM.

Affected Products and Versions

PowerKVM 2.1

Remediation/Fixes

Fix is made available via Fix Central (https://ibm.biz/BdEnT8) in 2.1.1 Build 65.1 and all later 2.1.1 SP3 service builds and 2.1.1 fix packs. For systems currently running fix levels of PowerKVM prior to 2.1.1, please see <http://download4.boulder.ibm.com/sar/CMA/OSA/05e4c/0/README&gt; for prerequisite fixes and instructions. Customers can also update from 2.1.1 (GA and later levels) by using “yum update”.

Workarounds and Mitigations

None