IBM Security Bulletin: Vulnerability in sendmail impacts AIX (CVE-2014-3956)

Share this post:

There is a vulnerability in sendmail that impacts AIX.

CVE(s): CVE-2014-3956

Affected product(s) and affected version(s):

AIX 5.3, 6.1, 7.1, 7.2
VIOS 2.2

The following fileset levels are vulnerable:

key_fileset = aix

Fileset                    Lower Level  Upper Level KEY
————————————————————
bos.net.tcp.client         5.3.12.0     5.3.12.10   key_w_fs
bos.net.tcp.server         5.3.12.0     5.3.12.6    key_w_fs
bos.net.tcp.client         6.1.9.0      6.1.9.315   key_w_fs
bos.net.tcp.client         7.1.4.0      7.1.4.32    key_w_fs
bos.net.tcp.client         7.1.5.0      7.1.5.15    key_w_fs
bos.net.tcp.sendmail       7.2.0.0      7.2.0.2     key_w_fs
bos.net.tcp.sendmail       7.2.1.0      7.2.1.1     key_w_fs
bos.net.tcp.sendmail       7.2.2.0      7.2.2.15    key_w_fs

Note: To find out whether the affected filesets are installed on your systems, refer to the lslpp command found in AIX user’s guide.

Example:  lslpp -L | grep -i bos.net.tcp.client

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://www-01.ibm.com/support/docview.wss?uid=isg3T1027341
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/93592



from IBM Product Security Incident Response Team https://ift.tt/2qezN42