IBM Security Bulletin: Multiple vulnerabilities in MD5 Signature and Hash Algorithm, glibc and OpenSSL affect IBM Netezza Firmware Diagnostics Tools

The MD5 “Sloth” vulnerability on TLS 1.2, glibc and OpenSSL are used by IBM Netezza Firmware Diagnostics Tools. IBM Netezza Firmware Diagnostics Tools has addressed the applicable CVEs.

CVE(s): CVE-2015-7575, CVE-2015-7547, CVE-2016-0705, CVE-2016-0798, CVE-2016-0797, CVE-2016-0799, CVE-2016-0702, CVE-2016-2842, CVE-2015-3197, CVE-2015-3194, CVE-2015-3195, CVE-2015-3196

Affected product(s) and affected version(s):

IBM Netezza Firmware Diagnostics Tools 4.3.1.1 (and prior releases).

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2chy8Xw
X-Force Database: http://ift.tt/1TnIyR8
X-Force Database: http://ift.tt/1rhWqTE
X-Force Database: http://ift.tt/1Tg5wqO
X-Force Database: http://ift.tt/1N2N4p3
X-Force Database: http://ift.tt/1Tg5wqQ
X-Force Database: http://ift.tt/1N2N4p5
X-Force Database: http://ift.tt/1Tg5v6h
X-Force Database: http://ift.tt/24fOBfM
X-Force Database: http://ift.tt/1rd26hw
X-Force Database: http://ift.tt/1KB3Vh1
X-Force Database: http://ift.tt/1QmYT4z
X-Force Database: http://ift.tt/1KB3SSD



from IBM Product Security Incident Response Team http://ift.tt/2c4BfyW