Lucene search

K
ibmIBMBEA663E577CD827F2C7D9FD6A2E59A21D9CFC5D0A3B8F2D59E92BD24A5D6CCD7
HistoryJun 18, 2018 - 1:34 a.m.

Security Bulletin: Vulnerabilities in PHP affect PowerKVM

2018-06-1801:34:16
www.ibm.com
21

0.242 Low

EPSS

Percentile

96.6%

Summary

PowerKVM is affected by numerous vulnerabilities in PHP. IBM has now addressed these vulnerabilities.

Vulnerability Details

CVEID: CVE-2016-5399**
DESCRIPTION:** PHP could allow a remote attacker to execute arbitrary code on the system, caused by an out-of-bounds write in the bzread() function. By sending a specially-crafted request, an attacker could exploit this vulnerability to upload a malformed PHP script to execute arbitrary code on the system.
CVSS Base Score: 7.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/115332 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)

CVEID: CVE-2016-5766**
DESCRIPTION:** PHP is vulnerable to a heap-based buffer overflow, caused by an integer overflow in the _gd2GetHeader() function. By sending an overly long argument, a remote attacker could overflow a buffer and execute arbitrary code on the system or cause the application to crash.
CVSS Base Score: 7.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/114386 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)

CVEID: CVE-2016-5767**
DESCRIPTION:** PHP is vulnerable to a heap-based buffer overflow, caused by an integer interflow in the gdImagePaletteToTrueColor() function. By sending an overly long argument, a remote attacker could overflow a buffer and execute arbitrary code on the system or cause the application to crash.
CVSS Base Score: 7.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/114387 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)

CVEID: CVE-2016-5768**
DESCRIPTION:** PHP could allow a remote attacker to execute arbitrary code on the system, caused by a double-free error in the _php_mb_regex_ereg_replace_exec. An attacker could exploit this vulnerability to execute arbitrary code on the system or cause the application to crash.
CVSS Base Score: 7.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/114388 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)

Affected Products and Versions

PowerKVM 3.1 only

Remediation/Fixes

Customers can update PowerKVM systems by using “yum update”.

Fix images are made available via Fix Central. For version 3.1, see https://ibm.biz/BdHggw. This issue is addressed as of 3.1.0.2 update 3 or later.

Workarounds and Mitigations

None

CPENameOperatorVersion
powerkvmeq3.1