IBM Support

Security Bulletin: ISC DHCP vulnerability affects TS4500 Tape Library (CVE-2018-5732)

Security Bulletin


Summary

The TS4500 Tape Library may be vulnerable to a denial of service attack if dynamic addressing (DHCP) is used.

Vulnerability Details

CVEID: CVE-2018-5732
DESCRIPTION:
ISC DHCP is vulnerable to a denial of service, caused by a buffer overflow in dhclient. By sending a specially crafted response, a remote attacker could overflow a buffer and possibly execute arbitrary code on the system or cause the server to crash.
CVSS Base Score: 7.5
CVSS Temporal Score: See http://exchange.xforce.ibmcloud.com/vulnerabilities/139613 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

Affected Products and Versions

Version 1.4.1.2 and lower.

Remediation/Fixes

Upgrade to version 1.4.1.3 or later.

Workarounds and Mitigations

Use static addressing for the library IP address and/or use a trusted DHCP server.

Get Notified about Future Security Bulletins

References

Off

Acknowledgement

None.

Change History

27 April 2018: Original version published.

*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.

Disclaimer

Review the IBM security bulletin disclaimer and definitions regarding your responsibilities for assessing potential impact of security vulnerabilities to your environment.

[{"Product":{"code":"STQRQ9","label":"IBM TS4500"},"Business Unit":{"code":"BU058","label":"IBM Infrastructure w\/TPS"},"Component":"Not Applicable","Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"Version Independent","Edition":"N\/A","Line of Business":{"code":"LOB26","label":"Storage"}},{"Product":{"code":"STQRQ9","label":"IBM TS4500"},"Business Unit":{"code":"BU058","label":"IBM Infrastructure w\/TPS"},"Component":" ","Platform":[{"code":"","label":""}],"Version":"","Edition":"","Line of Business":{"code":"LOB26","label":"Storage"}}]

Document Information

Modified date:
17 June 2018

UID

ssg1S1012247