Vulnerability Bulletins

IBM Security Bulletin: IBM General Parallel File System is affected by security vulnerabilities (CVE-2015-0197, CVE-2015-0198, CVE-2015-0199)

   
Affected software IBM
 
Security vulnerabilities have been identified in current levels of GPFS V4.1, V3.5, and V3.4: - could allow a local attacker which only has a non-privileged account to execute programs with root privileges (CVE-2015-0197) - may not properly authenticate network requests and could allow an attacker to execute programs remotely with root privileges (CVE-2015-0198) - allows attackers to cause kernel memory corruption by issuing specific ioctl calls to a character device provided by the mmfslinux

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_ibm_general_parallel_file_system_is_affected_by_security_vulnerabilities_cve_2015_0197_cve_2015_0198_cve_2015_0199?lang=en_us