Vulnerability Bulletins |
IBM Security Bulletin: Vulnerabilities in MD5 Signature and Hash Algorithm and TLS 1.2 affects sendmail, imap, and pop3d on AIX (CVE-2015-7575, CVE-2016-0266) |
|
| Affected software | IBM |
|
TLS 1.2 is not the default communication for sendmail, imap, and pop3d, and TLS 1.2 is impacted by the MD5 Sloth vulnerability.CVE(s): CVE-2015-7575, CVE-2016-0266Affected product(s) and affected version(s): AIX 5.3, 6.1, 7.1, 7.2 VIOS 2.2.x The following fileset levels are vulnerable: key_fileset = aix Fileset Lower Level Upper Level KEY --------------------------------------------------------- bos.net.tcp.client 5.3.12.0 5.3.12.10 key_w_fs bos.net.tcp.server 5.3.12.0 5.3.12.6 key_w_fs More info: https://www.ibm.com/blogs/psirt/ibm-vulnerabilities-in-md5-signature-and-hash-algorithm-and-tls-1-2-affects-sendmail-imap-and-pop3d-on-aix-cve-2015-7575-cve-2016-0266/ |
|






