Lucene search

K
ibmIBMB2B68C580CD4171A7F8B6F6C9AFDAF01A0B27307289C6197742BE7B8A33D5D39
HistoryJun 18, 2018 - 12:34 a.m.

Security Bulletin: Open Source OpenSSL Vulnerabilities affect IBM Network Advisor

2018-06-1800:34:55
www.ibm.com
22

EPSS

0.899

Percentile

98.9%

Summary

Open Source OpenSSL Vulnerabilities affect IBM Network Advisor (CVE-2016-7053, CVE-2016-7054, CVE-2016-7055

Vulnerability Details

CVEID: CVE-2016-7053**
DESCRIPTION:** OpenSSL is vulnerable to a denial of service, caused by a NULL pointer dereference when processing invalid encodings in the ASN.1 ‘‘CHOICE’’ type. By sending specially crafted cryptographic message syntax (CMS) structures, a remote attacker could exploit this vulnerability to cause the application to crash.
CVSS Base Score: 5.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/118746 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)

CVEID: CVE-2016-7054**
DESCRIPTION:** OpenSSL is vulnerable to a denial of service, caused by a heap-based buffer overflow. By sending specially crafted payloads via a TLS connection using -CHACHA20-POLY1305 ciphersuites, a remote attacker could exploit this vulnerability to overflow a buffer and cause the application to crash.
CVSS Base Score: 5.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/118747 for the current score
CVSS Environmental Score
: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)

CVEID: CVE-2016-7055**
DESCRIPTION:** OpenSSL is vulnerable to a denial of service, caused by an error in a Broadwell-specific Montgomery multiplication procedure. By sending specially crafted data, a remote attacker could exploit this vulnerability to trigger errors in public-key operations in configurations where multiple remote clients select an affected EC algorithm and cause a denial of service.
CVSS Base Score: 5.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/118748 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)

Affected Products and Versions

IBM Network Advisor prior to 14.0.2

Remediation/Fixes

Fixed in IBM Network Advisor 14.0.2

Workarounds and Mitigations

NA