IBM Security Bulletin: Vulnerabilities in NTP affect IBM Flex System FC3171 8Gb SAN Switch and SAN Pass-thru, QLogic 8Gb Intelligent Pass-thru Module & SAN Switch Module for BladeCenter and QLogic Virtual Fabric Extension Module for IBM BladeCenter

An information leak flaw and buffer overflow flaw in the way the OpenSSH client roaming feature was implemented affects IBM Flex System EN6131 40Gb Ethernet / IB6131 40Gb Infiniband Switch Firmware.

CVE(s): CVE-2016-1547, CVE-2016-1548, CVE-2016-1549, CVE-2016-1551,
CVE-2016-2516, CVE-2016-2517, CVE-2016-2518, CVE-2016-2519
Affected product(s) and affected version(s):

ProductAffected Version
IBM Flex System FC3171 8Gb SAN Switch and SAN Pass-thru Firmware
qlgc_fw_flex_9.1.9.02.00_anyos_noarch
9.1.9.02.00
QLogic 8Gb Intelligent Pass-thru Module & SAN Switch Module for BladeCenter
qlgc_fw_bcsw_7.10.1.40.00_anyos_noarch
7.10.1.40.00
QLogic Virtual Fabric Extension Module for IBM BladeCenter
qlgc_fw_bcsw_9.0.3.19.00_anyos_noarch
9.0.3.19.00

 

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2lrAVOr
X-Force Database: http://ift.tt/28MbfXh
X-Force Database: http://ift.tt/28PlwWo
X-Force Database: http://ift.tt/28MbjGw
X-Force Database: http://ift.tt/2az7WSa
X-Force Database: http://ift.tt/28Mbe5E
X-Force Database: http://ift.tt/28PlrCb
X-Force Database: http://ift.tt/28MbhOU
X-Force Database: http://ift.tt/28PlBcr



from IBM Product Security Incident Response Team http://ift.tt/2ll0TGC