Lucene search

K
ibmIBMF8291E336599F5A227A53EC80DFC02F77CB3F39D45D965D252BAC5441A410703
HistoryJul 30, 2018 - 10:30 p.m.

Security Bulletin: IBM BladeCenter Advanced Management Module (AMM) is affected by a vulnerability in freetype2 (CVE-2016-10328)

2018-07-3022:30:32
www.ibm.com
13

EPSS

0.009

Percentile

83.1%

Summary

IBM BladeCenter Advanced Management Module (AMM) has addressed the following vulnerability in freetype2.

Vulnerability Details

CVEID: CVE-2016-10328 DESCRIPTION: Freetype 2 is vulnerable to a heap-based buffer overflow, caused by an out-of-bounds write related to the cff_parser_run function in cff/cffparse.c. By sending a specially request, a remote attacker could overflow a buffer and execute arbitrary code on the system.
CVSS Base Score: 7.3
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/126666&gt; for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)

Affected Products and Versions

Product

|

Affected Version

—|—

IBM BladeCenter Advanced Management Module (AMM)

|

BPET

Remediation/Fixes

Firmware fix versions are available on Fix Central: http://www.ibm.com/support/fixcentral/

Product

|

Fix Version

—|—

IBM BladeCenter Advanced Management Module (AMM)
(ibm_fw_amm_bpet68j-3.68j_anyos_noarch)

|

bpet68j-3.68j

Workarounds and Mitigations

None

EPSS

0.009

Percentile

83.1%