IBM Support

LI79891: CMS KBD WEAKNESS VULNERABILITY AND OTHER REPORTED ISSUES

Subscribe to this APAR

By subscribing, you receive periodic emails alerting you to the status of the APAR, along with a link to the fix after it becomes available. You can track this item individually or track all items by product.

Notify me when this APAR changes.

Notify me when an APAR for this component changes.

 

APAR status

  • Closed as program error.

Error description

  • Communications Server for Data Center Deployment, V7
    Communications Server for AIX, V6.4
    Communications Server for Linux, V6.4
    Communications Server for Linux of System z, V6.4
    Communications Server for Windows, V6.4 and V6.1.3
    ----------------------------------------------------
    This fix addresses the following reported vulnerability. The
    GSKit CMS KDB logic fails to salt the hash function resulting in
    weaker than expected protection of passwords. A weak password
    may be recovered. Also, this APAR addresses vulnerabilities
    reported in OpenSSL libcrypt library for CVE-2017-3736 and
    CVE-2017-37.
    

Local fix

Problem summary

  • This fix addresses the following reported vulnerability. The
    GSKit CMS KDB logic fails to salt the hash function resulting in
    weaker than expected protection of passwords. A weak password
    may be recovered. Also, this APAR addresses vulnerabilities
    reported in OpenSSL libcrypt library for CVE-2017-3736 and
    CVE-2017-37.
    

Problem conclusion

  • Note: After update the administrator should change password to
    ensure the new password is stored more securely. Products should
    encourage customers to take this step as a high priority
    action.
    

Temporary fix

Comments

APAR Information

  • APAR number

    LI79891

  • Reported component name

    CS LINUX ON ZSE

  • Reported component ID

    5724I3400

  • Reported release

    640

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2018-01-31

  • Closed date

    2018-01-31

  • Last modified date

    2018-01-31

  • APAR is sysrouted FROM one or more of the following:

    IJ03789

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    CS LINUX ON ZSE

  • Fixed component ID

    5724I3400

Applicable component levels

[{"Business Unit":{"code":"BU058","label":"IBM Infrastructure w\/TPS"},"Product":{"code":"SSDMF3","label":"Communications Server for Linux on zSeries"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"640","Edition":"","Line of Business":{"code":"LOB35","label":"Mainframe SW"}}]

Document Information

Modified date:
31 January 2018