Lucene search

K
ibmIBMD8B250863238C046A54C09A85C8009F596E399D1BC415C09F32178FDB4C792F4
HistoryJun 17, 2018 - 5:08 a.m.

Security Bulletin: Vulnerability in OpenSSL affects Rational Tau (CVE-2015-3194)

2018-06-1705:08:14
www.ibm.com
39

EPSS

0.951

Percentile

99.4%

Summary

OpenSSL vulnerabilities were disclosed on December 3, 2015 by the OpenSSL Project. OpenSSL is used by Rational Tau. Rational Tau has addressed the applicable CVE (CVE-2015-3194).

Vulnerability Details

CVEID: CVE-2015-3194**
DESCRIPTION:** OpenSSL is vulnerable to a denial of service, caused by a NULL pointer dereference when verifying certificates via a malformed routine. An attacker could exploit this vulnerability using signature verification routines with an absent PSS parameter to cause any certificate verification operation to crash.
CVSS Base Score: 5.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/108503 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)

Affected Products and Versions

4.3, 4.3.0.1, 4.3.0.2, 4.3.0.3, 4.3.0.4, 4.3.0.5, 4.3.0.6, 4.3.0.6 Interim Fix 1, 4.3.0.6 Interim Fix 2, 4.3.0.6 Interim Fix 3, 4.3.0.6 Interim Fix 4, 4.3.0.6 Interim Fix 5

Remediation/Fixes

Upgrade to Rational Tau Interim Fix 6 for 4.3.0.6

Workarounds and Mitigations

None