IBM Support

Security Bulletin: Vulnerabilities in glibc could lead to a local or remote buffer overflow in IBM SOA Policy Gateway Pattern for Red Hat Enterprise Linux Server . (CVE-2015-1472, CVE-2013-7423)

Created by Anna Maciejkowicz on
Published URL:
https://www.ibm.com/support/pages/node/259933
259933

Security Bulletin


Summary

Vulnerabilities were found and fixed in the GNU C Library that could lead to buffer overflows and local leakage of sensitive information..

Vulnerability Details

CVE-2015-1472
Description: GNU glibc is vulnerable to a heap-based buffer overflow, caused by improper bounds checking by stdio-common/vfscanf.c. A remote attacker could overflow a buffer and execute arbitrary code on the system or cause a denial of service.
CVSS Base Score: 4.6
CVSS Temporal Score: https://exchange.xforce.ibmcloud.com/vulnerabilities/100635 for more information
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:M/Au:N/C:P/I:P/A:P)


CVE-2013-7423
Description: GNU glibc could allow a local attacker to obtain sensitive information, caused by the writing of DNS queries to random file descriptors under high load by the getaddrinfo() function. An attacker could exploit this vulnerability to obtain sensitive information.
CVSS Base Score: 1.2
CVSS Temporal Score: https://exchange.xforce.ibmcloud.com/vulnerabilities/100647 for more information
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:L/AC:H/Au:N/C:P/I:N/A:N)

Affected Products and Versions

IBM SOA Policy Gateway Pattern for Red Hat Enterprise Linux Server version 2.5

Remediation/Fixes

Fixes for these issues are currently only available in very recent releases of glibc, for which there is as yet no official Red Hat patch. Users who wish to mitigate this issue should download and apply glibc release 2.21 or later from the GNU web site.

Get Notified about Future Security Bulletins

References

Off

*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.

Disclaimer

Review the IBM security bulletin disclaimer and definitions regarding your responsibilities for assessing potential impact of security vulnerabilities to your environment.

[{"Product":{"code":"SSWLGF","label":"WebSphere Service Registry and Repository"},"Business Unit":{"code":"BU053","label":"Cloud & Data Platform"},"Component":"Security","Platform":[{"code":"PF016","label":"Linux"}],"Version":"2.5","Edition":"","Line of Business":{"code":"LOB45","label":"Automation"}}]

Document Information

Modified date:
15 June 2018

UID

swg21701019