-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

===========================================================================
             AUSCERT External Security Bulletin Redistribution

                               ESB-2014.0353
         Security Bulletin: Storage HMC OpenSSL upgrade to address
                       cryptographic vulnerabilities
                               17 March 2014

===========================================================================

        AusCERT Security Bulletin Summary
        ---------------------------------

Product:           IBM Storage HMC
Publisher:         IBM
Operating System:  Linux variants
Impact/Access:     Execute Arbitrary Code/Commands -- Remote/Unauthenticated
                   Denial of Service               -- Remote/Unauthenticated
                   Access Confidential Data        -- Remote/Unauthenticated
Resolution:        Patch/Upgrade
CVE Names:         CVE-2012-2131 CVE-2012-2110 CVE-2012-0884
                   CVE-2012-0050 CVE-2012-0027 CVE-2011-4619
                   CVE-2011-4577 CVE-2011-4576 CVE-2011-4108
                   CVE-2011-3210 CVE-2011-3207 CVE-2011-0014
                   CVE-2010-4252 CVE-2010-3864 CVE-2010-1633
                   CVE-2010-0742  

Reference:         ESB-2013.0760
                   ESB-2013.0537
                   ESB-2013.0526
                   ESB-2013.0487
                   ESB-2013.0309
                   ESB-2013.0300
                   ESB-2012.0732
                   ESB-2012.0713
                   ASB-2010.0135
                   ESB-2010.1048.2

Original Bulletin: 
   http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004564

- --------------------------BEGIN INCLUDED TEXT--------------------

Security Bulletin: Storage HMC OpenSSL upgrade to address cryptographic 
vulnerabilities.

Security Bulletin

Document information

More support for:
DS8870

Version:
7.1

Operating system(s):
Linux

Reference #:
S1004564

Modified date:
2014-03-13

Summary

Storage HMC included in releases prior to v7.2 use OpenSSL versions that had 
errors in cryptographic libraries that could allow remote attackers to conduct 
buffer overflow attacks, and cause a denial of service (memory corruption).

Vulnerability Details

CVE ID: CVE-2012-2131 CVE-2012-2110 CVE-2012-0884 CVE-2012-0050 CVE-2011-4108 
CVE-2011-4576 CVE-2011-4577 CVE-2011-4619 CVE-2012-0027 CVE-2011-3207 
CVE-2011-3210 CVE-2011-0014 CVE-2010-4252 CVE-2010-3864 CVE-2010-0742 
CVE-2010-1633

DESCRIPTION: Storage HMC included in release v7.2 includes a newer version of 
OpenSSL that resolves a number of key security exposures, and improves the 
entropy by mixing the time into the entropy pool .

CVE-2012-2131
CVSS Base Score: 7.5
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/75099 for the 
current score
CVSS Environmental Score*: Unknown
CVSS Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:P)

CVE-2012-2110
CVSS Base Score: 7.5
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/74926 for the 
current score
CVSS Environmental Score*: Unknown
CVSS Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:P)

CVE-2012-0884
CVSS Base Score: 5
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/73916 for the 
current score
CVSS Environmental Score*: Unknown
CVSS Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N)

CVE-2012-0050
CVSS Base Score: 4.3CVSS Temporal Score: See 
http://xforce.iss.net/xforce/xfdb/72458 for the current score
CVSS Environmental Score*: Unknown
CVSS Vector: (AV:N/AC:M/Au:N/C:N/I:N/A:P)

CVE-2011-4108
CVSS Base Score: 4.3
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/72128 for the 
current score
CVSS Environmental Score*: Unknown
CVSS Vector: (AV:N/AC:M/Au:N/C:P/I:N/A:N)

CVE-2011-4576
CVSS Base Score: 5
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/72130 for the 
current score
CVSS Environmental Score*: Unknown
CVSS Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N)

CVE-2011-4577
CVSS Base Score: 4.3
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/72131 for the 
current score
CVSS Environmental Score*: Unknown
CVSS Vector: (AV:N/AC:M/Au:N/C:N/I:N/A:P)

CVE-2011-4619
CVSS Base Score: 4.3
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/72132 for the 
current score
CVSS Environmental Score*: Unknown
CVSS Vector: (AV:N/AC:M/Au:N/C:N/I:N/A:P)

CVE-2011-3210
CVSS Base Score: 5
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/69614 for the 
current score
CVSS Environmental Score*: Unknown
CVSS Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:P)

CVE-2011-0014
CVSS Base Score: 5.8
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/68221 for the 
current score
CVSS Environmental Score*: Unknown
CVSS Vector: (AV:N/AC:M/Au:N/C:P/I:N/A:P)

CVE-2010-3864
CVSS Base Score: 6.8
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/63293 for the 
current score
CVSS Environmental Score*: Unknown
CVSS Vector: (AV:N/AC:M/Au:N/C:P/I:P/A:P)
Affected Products and Versions

DS8870 v7.0 and v7.1

Remediation/Fixes

Upgrade to storage release v7.2

Workarounds and Mitigations

No workarounds or mitigations - Upgrade to storage release v7.2

References

Complete CVSS Guide
On-line Calculator V2
Complete CVSS Guide
On-line Calculator V2
CVE-2012-2131
CVE-2012-2110
CVE-2012-0884
CVE-2012-0050
CVE-2011-4108
CVE-2011-4576
CVE-2011-4577
CVE-2011-4619
CVE-2011-3210
CVE-2011-0014
CVE-2010-3864

Related information

IBM Secure Engineering Web Portal
IBM Product Security Incident Response Blog
IBM Secure Engineering Web Portal
IBM Product Security Incident Response Blog

Change History

9 March 2014: first version

*The CVSS Environment Score is customer environment specific and will 
ultimately impact the Overall CVSS Score. Customers can evaluate the impact of 
this vulnerability in their environments by accessing the links in the 
Reference section of this Security Bulletin.

Disclaimer

According to the Forum of Incident Response and Security Teams (FIRST), the 
Common Vulnerability Scoring System (CVSS) is an "industry open standard 
designed to convey vulnerability severity and help to determine urgency and 
priority of response." IBM PROVIDES THE CVSS SCORES "AS IS" WITHOUT WARRANTY 
OF ANY KIND, INCLUDING THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS 
FOR A PARTICULAR PURPOSE. CUSTOMERS ARE RESPONSIBLE FOR ASSESSING THE IMPACT 
OF ANY ACTUAL OR POTENTIAL SECURITY VULNERABILITY.

- --------------------------END INCLUDED TEXT--------------------

You have received this e-mail bulletin as a result of your organisation's
registration with AusCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.

NOTE: Third Party Rights
This security bulletin is provided as a service to AusCERT's members.  As
AusCERT did not write the document quoted above, AusCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AusCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.

NOTE: This is only the original release of the security bulletin.  It may
not be updated when updates to the original are made.  If downloading at
a later date, it is recommended that the bulletin is retrieved directly
from the author's website to ensure that the information is still current.

Contact information for the authors of the original document is included
in the Security Bulletin above.  If you have any questions or need further
information, please contact them directly.

Previous advisories and external security bulletins can be retrieved from:

        http://www.auscert.org.au/render.html?cid=1980

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
===========================================================================
-----BEGIN PGP SIGNATURE-----
Comment: http://www.auscert.org.au/render.html?it=1967

iQIVAwUBUyaaNRLndAQH1ShLAQLf8Q//csn7RKm61apc0syNuF2ihaafq6jmUIAV
ssbFnCdINw8vC09LzaTNG+gTExJEYrwnxFqgJyyOa8HxDkW+P+ainEHokq95reEv
L2hOUJuLPrUacMvnjytKXFG8CHNKcQjLLsXLWIIk7/d/INszKrwgjBjmu/6YkCap
ZbgBbaliF74l5L4CPT7AtWI0Q//xZU/M+fE9H1TILovE1ynbYeEVl9g7GMkpyurp
QYJEi+hOeLdxFIx7Jq8A8x8s1OIIWZ2xuxxMSvowJMkDnaKRK/WbQ5mHLVzt8W1c
+KZplEy0PSRNgLCRkqXDUZ3KGRAeTOLUEXzajnFiEaLYaK5Bq7M0gyCxPoaqlE+W
Nc2jeJCWlFhNela+2fc19Zzncp2Y862/VPkg7fim8e8xrP1jixFiVEByxObjgfRV
rNsJL1zHiMey1iW1XBHSCsKjsbWZ8++ICykDK77k9SYDFl0ueVzRzAu9VHytqCx4
yMFugk/ga3xvfbpraGrFZ0E2TZN+wa7ayQ/Z4ahxmpVsafcNrCJBFGcjjvoeujQH
365KgPF4b1DMmkg96InkkuQh8DVwvdVdsBizEyC5aJ5gh0L5RstEPsJ14f8AdC/Z
yAc67zr2SOO6mrdItRhYsqJefoBarVgK8iUvnqBqxm6rQLUuAl+IjfovL+w4LHg8
W95mZwrnZKA=
=7dBf
-----END PGP SIGNATURE-----