-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

===========================================================================
                         AUSCERT Security Bulletin

                               ASB-2014.0052
    A high severity vulnerability has been discovered in Dell SonicWALL
                               15 April 2014

===========================================================================

        AusCERT Security Bulletin Summary
        ---------------------------------

Product:              Dell SonicWALL SMB Secure Remote Access
                      Dell SonicWALL E-Class Secure Remote Access
                      Dell SonicWALL Global Management System (GMS) and Analyzer
Operating System:     Network Appliance
                      Windows
Impact/Access:        Access Privileged Data -- Remote/Unauthenticated
Resolution:           Patch/Upgrade
CVE Names:            CVE-2014-0160  
Member content until: Thursday, May 15 2014
Reference:            ASB-2014.0042
                      ESB-2014.0457

OVERVIEW

        A high severity vulnerability has been discovered in Dell SonicWALL 
        products.


IMPACT

        The vendor has provided the following details regarding this
        vulnerability:
        
        'Dell SonicWALL Notice Concerning CVE-2014-0160 OpenSSL Large Heartbleed 
        Response Vulnerability 
                                                                                                                   
        Researchers have found a critical defect in versions 1.0.1 and 1.0.2-beta 
        of OpenSSL, the cryptographic software library. For information on the 
        vulnerability known as the "Heartbleed bug," see CVE-2014-0160 on the 
        NIST website and heartbleed.com.' [1]


MITIGATION

        The vendor recommends applying relevant patches or upgrading to the latest 
        version of all affected products.


REFERENCES

        [1] Dell SonicWALL Notice Concerning CVE-2014-0160 OpenSSL Large
            Heartbeat Response Vulnerability
            https://www.fuzeqna.com/sonicwallkb/ext/kbdetail.aspx?kbid=11180

AusCERT has made every effort to ensure that the information contained
in this document is accurate.  However, the decision to use the information
described is the responsibility of each user or organisation. The decision to
follow or act on information or advice contained in this security bulletin is
the responsibility of each user or organisation, and should be considered in
accordance with your organisation's site policies and procedures. AusCERT
takes no responsibility for consequences which may arise from following or
acting on information or advice contained in this security bulletin.

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours 
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
===========================================================================
-----BEGIN PGP SIGNATURE-----
Comment: http://www.auscert.org.au/render.html?it=1967

iQIVAwUBU0yc6xLndAQH1ShLAQLo0A//RXAkz8ARZJFJvmU2cldlRF2SMSawFiEZ
aPV+a+sK2yTEHfIVNZd0pdU11WHgWAO4oIhqMXUioUd7BYO190Tp017uRfKSrtP6
SLA+GYQAN2qAR3XAGErz0szdg3XnFPHX8a+ityoSvX7OmUlomD7DGU5xbrCyDT/w
ACHeuDqb4rziy8hMBGQCWnAfv28HCMLhrChxhn562F5fuCAAu7IICJcl2fWsvhz1
ZGlYCaGBajBZ9m/vN4glKK/FYZK8HoomZtT3f8OwPTHPlfmKZOFbNcmRQk9QUH1x
eU3MzUiePfd6kX1oO54y+rrLTKEOsvGggZ1PabvPCj/hQ4N1YEp6mR3OIhwFLvEz
mQ9BBasGvW124B5aGqhuDPNDa2EhaDVnmmtRxbU2ofO4MHzzkEzBDrOJuDPUoAw+
Gc+UR/5h94ExGW7cmfUp9jRkgnEYSVsUC7y/pqcShsHTE63Xw1DKrXllhPCXRL7s
BIMml37d7hJ8ARRuutzqHZs0+vczgxlNO/FwiGUjYgb0mKYAOWjM1TAA0wfEKuNF
mT/N1HiffA4Ul2DXzsigJIDmMqrxtg6TyzNTA7Xy94XNTVocTc4Z5Ygu9VBkQxhG
JgTi5rMH3SHUn0AIsS6SkAoKKTpG3d8WZozouLck/+K+dVdbcN9fi06UGijJmwOm
8sen7HeJyuk=
=Bdub
-----END PGP SIGNATURE-----