Vulnerability Bulletins

IBM Security Bulletin: Vulnerability in cURL component shipped with IBM Rational ClearCase (CVE-2015-3153)

   
Affected software IBM
 
IBM Rational ClearCase is affected by a cURL/libcURL CURLOPT_HTTPHEADER information disclosure vulnerability. CVE(s): CVE-2015-3153 Affected product(s) and affected version(s): The cURL component is used in the CMI integration, the OSLC-based ClearQuest integration, and in the automatic view client. ClearCase client version Status 8.0.1 through 8.0.1.8 Affected 8.0 through 8.0.0.15 Affected 7.1.2 through 7.1.2.18 Affected 7.1.0.x, 7.1.1.x (all versions and fix

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_vulnerability_in_curl_component_shipped_with_ibm_rational_clearcase_cve_2015_3153?lang=en_us