IBM Support

PI09443: Potential denial of service vulnerability in IBM HTTP Server

Download


Abstract

This interim fix upgrades the GSKit shipped with IBM HTTP Server to resolve the CVE-2013-6747 vulnerability.

Download Description

PI09443 resolves the following problem:

USERS AFFECTED:
Users of IBM HTTP Server with SSL enabled.

PROBLEM DESCRIPTION:
A GSKit security library problem could result in hang or crash of IBM HTTP Server.

RECOMMENDATION:
Apply this fix if using IBM HTTP Server with SSL enabled.

PROBLEM CONCLUSION:
The GSKit security library was updated to resolve the issue.

This fix is targeted for IBM HTTP Server fixpacks:
- 7.0.0.33
- 8.0.0.9
- 8.5.5.2


IBM HTTP Server is distributing an updated GSKit security library as an interim fix.
The fix for PI08502 is also included in this interim fix.
No configuration is required once GSKit is updated to 7.0.4.48 or 8.0.50.17.

Note: For IHS 8.5.5, the fix is in the 8.5.5.2 fixpack , but "CVE-2013-6747" will not be listed in
the '-V' output until the 8.5.5.3 fixpack.


For IHS version 8.0 and 8.5:

The interim fix can be installed using Installation Manager (IM) with the Web-based ("live") repository provided by IBM. It may be necessary to de-select the "Show recommended only" option within IM and to expand "Only fixes for version 8.x.y.z" to see the fix listed.
The interim fix is also available from Fix Central at the link listed in the Download Package section below.

For IHS versions prior to 8.0:

This standalone GSKit update has been published to the IBM HTTP Server Fixes download site,
and is located under the 'GSKit Version 7' section for your platform. Click 'here' to be taken to the login page.

For IBM HTTP Server 6.x releases, download the GSKit 7.0.4.48 package and Readme
under the section labeled 'PI09443 - IHS Version 6'

For IBM HTTP Server 7.0 releases, download the GSKit 7.0.4.48 package and Readme
under the section labeled 'PI09443 - IHS Version 7'

Installation Instructions

Review the readme.txt available with the fix for installation instructions.

Download Package

Fixes for IHS V6 and V7 must be downloaded as described above from the IBM HTTP Server Fixes download site.

On
[{"DNLabel":"Fix for 8.0.0.0 - 8.0.0.8","DNDate":"10 Feb 2014","DNLang":"US English","DNSize":"151003893","DNPlat":{"label":"AIX","code":"PF002"},"DNURL":"http:\/\/www.ibm.com\/support\/fixcentral\/quickorder?fixids=8.0.0.0-WS-WASIHS_GSKit-MultiOS-IFPI09443&product=ibm%2FWebSphere%2FWebSphere%20Application%20Server&source=dbluesearch","DNURL_FTP":" ","DDURL":" "},{"DNLabel":"Fix for 8.5.0.0 - 8.5.5.1","DNDate":"10 Feb 2014","DNLang":"US English","DNSize":"150950424","DNPlat":{"label":"AIX","code":"PF002"},"DNURL":"http:\/\/www.ibm.com\/support\/fixcentral\/quickorder?fixids=8.5.0.0-WS-WASIHS_GSKit-MultiOS-IFPI09443&product=ibm%2FWebSphere%2FWebSphere%20Application%20Server&source=dbluesearch","DNURL_FTP":" ","DDURL":" "}]

Technical Support

Contact IBM Support using SR (http://www.ibm.com/software/support/probsub.html), visit the WebSphere Application Server support web site (http://www.ibm.com/software/webservers/appserv/was/support/), or contact 1-800-IBM-SERV (U.S. only).

[{"Product":{"code":"SSEQTP","label":"WebSphere Application Server"},"Business Unit":{"code":"BU004","label":"Hybrid Cloud"},"Component":"IBM HTTP Server","Platform":[{"code":"PF002","label":"AIX"},{"code":"PF010","label":"HP-UX"},{"code":"PF016","label":"Linux"},{"code":"PF027","label":"Solaris"},{"code":"PF033","label":"Windows"}],"Version":"8.5.5;8.5;8.0;7.0;6.1","Edition":"Advanced;Base;Enterprise;Express;Network Deployment;Single Server"}]

Document Information

Modified date:
15 June 2018

UID

swg24036992