IBM QRadar Network Security has addressed the denial of service vulnerability in cURL.
CVEID: CVE-2017-1000257**
DESCRIPTION:** cURL is vulnerable to a denial of service, caused by a buffer overread in the IMAP handler. By using a specially crafted IMAP FETCH response, a remote attacker could exploit this vulnerability to cause the application to crash or obtain sensitive information.
CVSS Base Score: 6.5
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/134033 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L)
IBM QRadar Network Security 5.4
Product
| VRMF| Remediation/First Fix
โ|โ|โ
IBM QRadar Network Security| Firmware version 5.4| Install Firmware 5.4.0.4 from the Available Updates page of the Local Management Interface, or by performing a One Time Scheduled Installation from SiteProtector.
Or
Download Firmware 5.4.0.4 from IBM Security License Key and Download Center and upload and install via the Available Updates page of the Local Management Interface.
None
CPE | Name | Operator | Version |
---|---|---|---|
ibm qradar network security | eq | 5.4 |