IBM Support

Security Bulletin: Mozilla firefox vulnerability issues on SONAS (CVE-2013-5590, CVE-2013-5595, CVE-2013-5597, CVE-2013-5599, CVE-2013-5600, CVE-2013-5601, CVE-2013-5602, CVE-2013-5604)

Created by Ana Gabriela I… on
Published URL:
https://www.ibm.com/support/pages/node/689483
689483

Security Bulletin


Summary

SONAS is shipped with Mozilla firefox, for which fixes are available for security vulnerabilities.

Vulnerability Details

CVE ID:
CVE-2013-5590
CVE-2013-5595
CVE-2013-5597
CVE-2013-5599
CVE-2013-5600
CVE-2013-5601
CVE-2013-5602
CVE-2013-5604


DESCRIPTION:

SONAS is shipped with Mozilla firefox. For the above security vulnerabilities in Mozilla firefox, fixes are available. None of these vulnerabilities are exploitable during usual operations of the SONAS. Nevertheless, since using firefox to access the Internet would implicate these vulnerabilities, it is recommended to apply the fix.

CVE-2013-5590
CVSS Base Score: 9.3
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/88390 for the current score

CVE-2013-5595
CVSS Base Score: 9.3
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/88397 for the current score

CVE-2013-5597
CVSS Base Score: 9.3
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/88399 for the current score

CVE-2013-5599
CVSS Base Score: 9.3
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/88401 for the current score

CVE-2013-5600
CVSS Base Score: 9.3
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/88402 for the current score

CVE-2013-5601
CVSS Base Score: 9.3
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/88403 for the current score

CVE-2013-5602
CVSS Base Score: 9.3
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/88404 for the current score

CVE-2013-5604
CVSS Base Score: 7.1
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/88395 for the current score

Affected Products and Versions

SONAS V1.3.0.0 to V1.4.2.1.

Remediation/Fixes

The fix for this issue is available beginning with SONAS V1.4.3.0. Customers running an earlier version of SONAS should upgrade to V1.4.3.0 or later in order to get these fixes.

Workarounds and Mitigations

Work-around(s): None.

Mitigation(s): None of these vulnerabilities are exploitable during usual operations of SONAS system. Use of Mozilla firefox for accessing web sites from SONAS system should be avoided.

Get Notified about Future Security Bulletins

References

Off

Acknowledgement

None

Change History

10 April 2014: First draft.

*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.

Disclaimer

Review the IBM security bulletin disclaimer and definitions regarding your responsibilities for assessing potential impact of security vulnerabilities to your environment.

[{"Product":{"code":"STAV45","label":"Network Attached Storage (NAS)->Scale Out Network Attached Storage"},"Business Unit":{"code":"BU054","label":"Systems w\/TPS"},"Component":"1.4.3.1","Platform":[{"code":"PF016","label":"Linux"}],"Version":"1.4","Edition":"","Line of Business":{"code":"","label":""}}]

Document Information

Modified date:
17 June 2018

UID

ssg1S1004574