IBM Security Bulletin: Vulnerability in OpenSSH affects AIX (CVE-2018-15473) Security Bulletin

Oct 25, 2018 9:01 am EDT

Categorized: Medium Severity

Share this post:

Vulnerability in OpenSSH affects AIX.

CVE(s): CVE-2018-15473

Affected product(s) and affected version(s):

AIX 5.3, 6.1, 7.1, 7.2
VIOS 2.2.x

The following fileset levels are vulnerable:

key_fileset = osrcaix

Fileset Lower Level Upper Level KEY
————————————————————-
openssh.base.client 4.0.0.5200 7.5.102.1500 key_w_fs
openssh.base.server 4.0.0.5200 7.5.102.1500 key_w_fs

Note: To determine if your system is vulnerable, execute the following commands:

lslpp -L | grep -i openssh.base.client
lslpp -L | grep -i openssh.base.server

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: https://www-01.ibm.com/support/docview.wss?uid=ibm10733751
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/148397



from IBM Product Security Incident Response Team https://ift.tt/2ESYgWS