SB2018041703 - Multiple vulnerabilities in IBM WebSphere MQ
Published: April 17, 2018 Updated: June 12, 2018
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 3 secuirty vulnerabilities.
1) Out-of-bounds read (CVE-ID: CVE-2017-3735)
The vulnerability allows a remote attacker to perform spoofing attack.
The vulnerability exists due to one-byte out-of-bounds read when parsing an IPAddressFamily extension in an X.509 certificate. A remote attacker can disguise text display of the certificate.
2) Carry propagation issue (CVE-ID: CVE-2017-3736)
The vulnerability allows a remote attacker to decrypt data.The vulnerability exists due to carry propagating bug in the x86_64 Montgomery squaring procedure (bn_sqrx8x_internal). A remote attacker can decrypt encrypted data. The vulnerability affects processors that support the BMI1, BMI2 and ADX extensions like Intel Broadwell (5th generation) and later or AMD Ryzen.
3) Resource exhaustion (CVE-ID: CVE-2017-1786)
The vulnerability allows a remote authenticated attacker to cause DoS condition on the target system.
The vulnerability exists due to memory leak. A remote attacker can trigger resource exhaustion and cause the service to crash.
Remediation
Install update from vendor's website.
References
- http://www-01.ibm.com/support/docview.wss?uid=swg22013026&myns=swgws&mynp=OCSSYHRD&mynp=OCSSFKSJ&mync=E&cm_sp=swgws-_-OCSSYHRD-OCSSFKSJ-_-E
- http://www-01.ibm.com/support/docview.wss?uid=swg22013025&myns=swgws&mynp=OCSSYHRD&mynp=OCSSFKSJ&mync=E&cm_sp=swgws-_-OCSSYHRD-OCSSFKSJ-_-E
- http://www-01.ibm.com/support/docview.wss?uid=swg22013023