Lucene search

K
ibmIBMFE692363647D6C7DE11E8A756A883CC7B949FF1AA679EC79419B7F4748282CBE
HistoryJun 17, 2018 - 10:30 p.m.

Security Bulletin: Vulnerability in gdk-pixbuf affects IBM SmartCloud Provisioning for IBM Software Virtual Appliance

2018-06-1722:30:13
www.ibm.com
16

EPSS

0.013

Percentile

85.8%

Summary

Vulnerability in gdk-pixbuf affects IBM SmartCloud Provisioning 2.1 for IBM Software Virtual Appliance (CVE-2015-4491).

Vulnerability Details

CVEID: CVE-2015-4491

DESCRIPTION: Mozilla Firefox is vulnerable to a heap-based buffer overflow, caused by improper bounds checking by gdk-pixbuf affecting Linux systems using Gnome. By persuading a victim to visit a specially-crafted Web site, a remote attacker could overflow a buffer and execute arbitrary code on the system or cause the application to crash.
CVSS Base Score: 8.8
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/105544&gt; for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)

Affected Products and Versions

IBM SmartCloud Provisioning 2.1 for IBM Software Virtual Appliance.

Remediation/Fixes

If you are running IBM SmartCloud Provisioning 2.1 for IBM Software Virtual Appliance, contact IBM support.

Workarounds and Mitigations

None