IBM Security Bulletin: Vulnerabilities in OpenSSH affect IBM Flex System EN6131 40Gb Ethernet / IB6131 40Gb Infiniband Switch Firmware (CVE-2016-0777, CVE-2016-0778)

An information leak flaw and buffer overflow flaw in the way the OpenSSH client roaming feature was implemented affects IBM Flex System EN6131 40Gb Ethernet / IB6131 40Gb Infiniband Switch Firmware.

CVE(s): CVE-2016-0777, CVE-2016-0778

 

Affected product(s) and affected version(s):

ProductAffected Version
IBM Flex System EN6131 40Gb Ethernet / IB6131 40Gb Infiniband Switch Firmware3.3 – 3.5

 

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2k3S6Vd
X-Force Database: http://ift.tt/1SXVjUy
X-Force Database: http://ift.tt/1Ph2CR4



from IBM Product Security Incident Response Team http://ift.tt/2k9WhRI