Lucene search

K
ibmIBMB421F565F5320C0CF5D897491C3184A2AF21365274B4A66C48EC3D25B1378465
HistoryFeb 11, 2019 - 4:15 p.m.

Security Bulletin: IBM InfoSphere Change Data Capture is affected by Apache Commons Codec open source library vulnerabilities

2019-02-1116:15:01
www.ibm.com
17

EPSS

0.061

Percentile

93.6%

Summary

InfoSphere Data Replication has addressed the following vulnerabilities:
CVE-2010-0001
CVE-2009-0001

Vulnerability Details

CVEID: CVE-2010-0001 DESCRIPTION: GNU gzip could allow a remote attacker to execute arbitrary code on the system caused by an integer underflow in the unlzw() function. By persuading a victim to open a specially-crafted LZW archive file, a remote attacker could exploit this vulnerability to execute arbitrary code on the system with the privileges of the user.
CVSS Base Score: 6.8
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/55788&gt; for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:M/Au:N/C:P/I:P/A:P)

CVEID: CVE-2009-0001 DESCRIPTION: Apple QuickTime is vulnerable to a heap-based buffer overflow, caused by improper bounds checking when processing RTSP URLs. By persuading a victim to open a specially-crafted RTSP URL, a remote attacker could overflow a buffer and execute arbitrary code on the system or cause the application to crash.
CVSS Base Score: 6.8
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/48154&gt; for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:M/Au:N/C:P/I:P/A:P)

Affected Products and Versions

InfoSphere Data Replication 11.4

Remediation/Fixes

Product VRMF APAR Remediation / First Fix
InfoSphere Data Replication

IIDR 11.4.0.2-5095 for all LUW engines

| N/A | Please download the latest release available in Fix Central: https://www-945.ibm.com/support/fixcentral/swg/selectFixes?parent=ibm~Information%20Management&product=ibm/Information+Management/IBM+InfoSphere+Data+Replication&release=11.4&platform=All&function=all&source=fc

Workarounds and Mitigations

N/A