IBM Support

JR52865: GSKIT EPHEMERAL RSA VULNERABILITY CVE-2015-0138

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • Communications Server for Data Center Deployment, V7
    Communications Server for Linux on System z, V6.4
    Communications Server for Linux, V6.4
    Communications Server for AIX, V6.4
    Communications Server for Windows, V6.1.3 and V6.4
    ----------------------------------------------------
    GSKit will accept a Weak Ephemeral RSA Key for non-export
    CipherSuites in SSLV3.0 and TLS 1.0. This means a hostile server
    that the Client trusts could potentially weaken its own security
    with the Client by downgrading the strength of the connection.
    This version fixes this by preventing RSA Export ciphers from
    being used.
    

Local fix

Problem summary

  • This APAR provides an updated GSKit package.
    

Problem conclusion

  • This APAR provides an updated GSKit package:
    
    For Communications Server for Windows, V6.1.3:
      GSKit 7.0.5.5
    
    For Communications Server for Windows, V6.4;
        Communications Server for AIX, V6.4;
        Communications Server for Linux, V6.4;
        Communications Server for Linux on System z, V6.4;
        Communications Server for Data Center Deployment, V7:
      GSKit 8.0.50.41
    

Temporary fix

Comments

APAR Information

  • APAR number

    JR52865

  • Reported component name

    COMM SERV NT 6.

  • Reported component ID

    5639F2503

  • Reported release

    640

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt

  • Submitted date

    2015-03-19

  • Closed date

    2015-03-19

  • Last modified date

    2015-03-19

  • APAR is sysrouted FROM one or more of the following:

    JR52855

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    COMM SERV NT 6.

  • Fixed component ID

    5639F2503

Applicable component levels

  • R640 PSY

       

[{"Business Unit":{"code":"BU058","label":"IBM Infrastructure w\/TPS"},"Product":{"code":"SSHQNF","label":"Communications Server for Windows"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"640","Line of Business":{"code":"LOB35","label":"Mainframe SW"}}]

Document Information

Modified date:
14 October 2021