-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

===========================================================================
                         AUSCERT Security Bulletin

                               ASB-2014.0058
              Novell Storage Manager 3.1.1.1 "Heartbleed Fix"
                                7 May 2014

===========================================================================

        AusCERT Security Bulletin Summary
        ---------------------------------

Product:              Novell Storage Manager
Operating System:     Windows
Impact/Access:        Access Privileged Data -- Remote/Unauthenticated
Resolution:           Patch/Upgrade
CVE Names:            CVE-2014.0160  
Member content until: Friday, June  6 2014

OVERVIEW

        A vulnerability has been identified in Novell Storage Manager prior to
        version 3.1.1.1. [1]


IMPACT

        The vendor has provided the following details regarding this 
        vulnerability:
        
        "This new build includes OpenSSL version 1.0.1g-which is a fix for 
        the "Heartbleed" vulnerability that can expose encrypted data being
        transmitted between components and a web browser." [1]


MITIGATION

        The vendor recommends updating to the latest version of Novell Storage
        manager to correct this issue. [1]


REFERENCES

        [1] Novell Storage Manager 3.1.1.1 "Heartbleed Fix"
            http://www.storagemanagersupport.com/nsm/

AusCERT has made every effort to ensure that the information contained
in this document is accurate.  However, the decision to use the information
described is the responsibility of each user or organisation. The decision to
follow or act on information or advice contained in this security bulletin is
the responsibility of each user or organisation, and should be considered in
accordance with your organisation's site policies and procedures. AusCERT
takes no responsibility for consequences which may arise from following or
acting on information or advice contained in this security bulletin.

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours 
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
===========================================================================
-----BEGIN PGP SIGNATURE-----
Comment: http://www.auscert.org.au/render.html?it=1967

iQIVAwUBU2mBwRLndAQH1ShLAQIPIQ/9GZsQgX1ihm0/lzeInrfmFwN/c1/LysYL
C3uyvsOpIgXBsxFcXlBfYAQ3rctVc0k2nEJws6gkM+9PC1sxRzbKUxMzw9Rdc6Qj
ZM7Xp0PWSX3aL4WY4b99mO+JtzSrAYF3tYC7Krqg4GKHPGBXCu/Ntuh+DVSkKSuU
tn6eFyTEi5yVtFlwWUDzIa2lgaAhABdVgJBY0IpkX9hLQ5abc56yZmM9tJ2v5KFx
KIvwu5HH0vkmAnXRxVNuOhJUG+MliaK4tyQBhPgZyiIVco5eUQnTQFObhQvsvEXj
SzIfscffzxHjcvXpKDsUfS3tUI0Ff1MJ4fsOWRwJTKUzwVpb9GhuMOlTgL8ObPq+
RZF0utZImjcV3oNVaBAehutZqncFCvE2sqTswKH0VFrteJvRbl0dWi/65yXDyak7
//4ZTvki73lMO73a+e2VLqVmNYZMys9u32Qcwm+PWgVefpQqniiVqWjiDA+YeNdQ
WsuEos/3ZSgaZcq7m6zfOQFIR+uz3rdqZB/Sevmjx+ERJTIhw679/9aNNo0DAQ+h
F6LRJbPdEtnAA7K/5YxXU+kovEMp1aFh2NvJoOafOKal7y1Io1SLnDhCX3R1Igmu
bB+bbRrtvdzNLiSw54nmZ8swK+fPkqYc8BBWobqljGqoPlzudK88c+jaLkGIMYzB
b5+SkEfwVsc=
=CO4A
-----END PGP SIGNATURE-----