Boletines de Vulnerabilidades

IBM Security Bulletin: OpenSSL security vulnerabilities on IBM SONAS (CVE-2014-3505, CVE-2014-3506, CVE-2014-3507, CVE-2014-3508, CVE-2014-3509, CVE-2014-3510, CVE-2014-3511)


Información sobre el sistema

   
Software afectado IBM

Descripción

A fix is available for IBM SONAS, for the OpenSSL security vulnerabilities CVE(s): CVE-2014-3505, CVE-2014-3506, CVE-2014-3507, CVE-2014-3508, CVE-2014-3509, CVE-2014-3510 and CVE-2014-3511 Affected product(s) and affected version(s): IBM SONAS The product is affected when running a code releases 1.3.0.0 to 1.4.3.4 Refer to the following reference URLs for remediation and additional vulnerability details: Source Bulletin: http://www.ibm.com/support/docview.wss?uid=ssg1S1004917 X-Force

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_openssl_security_vulnerabilities_on_ibm_sonas_cve_2014_3505_cve_2014_3506_cve_2014_3507_cve_2014_3508_cve_2014_3509_cve_2014_3510_cve_2014_3511?lang=en_us

Identificadores estándar

Propiedad Valor
CVE CVE-2014-3505 ,CVE-2014-3506 ,CVE-2014-3507 ,CVE-2014-3508 ,CVE-2014-3509 ,CVE-2014-3510 ,CVE-2014-3511 ,CVE-2014-6271 ,CVE-2014-7169 ,CVE-2014-7186 ,CVE-2014-7187 ,CVE-2014-6277 and CVE-2014-6278.

Histórico de versiones

Versión Comentario Fecha
1.0 Advisory issued 2014-10-14

Miembros de

Ministerio de Defensa
CNI
CCN
CCN-CERT