Security Bulletin: Vulnerabilities in OpenSSL affect AIX (CVE-2019-1547, CVE-2019-1563)

Nov 26, 2019 7:00 pm EST

Categorized: Medium Severity

Share this post:

There are vulnerabilities in OpenSSL used by AIX.

Affected product(s) and affected version(s):

Affected Product(s)Version(s)
AIX7.1
AIX7.2
VIOS2.2
VIOS3.1

 

The following fileset levels are vulnerable:

        

key_fileset = osrcaix

 

FilesetLower LevelUpper LevelKey
openssl.base1.0.2.5001.0.2.1801key_w_fs
openssl.base20.13.102.100020.16.102.1801key_w_fs

 

Note:

        A. 0.9.8, 1.0.1 OpenSSL versions are out-of-support. Customers are advised to upgrade to currently supported OpenSSL 1.0.2 version.

 

        B. Latest level of OpenSSL fileset is available from the web download site:

  

To find out whether the affected filesets are installed on your systems, refer to the lslpp command found in the AIX user's guide.

 

Example:  lslpp -L | grep -i openssl.base

Refer to the following reference URLs for remediation and additional vulnerability details:  
Source Bulletin: https://www.ibm.com/support/pages/node/1116033



from IBM Product Security Incident Response Team https://ift.tt/2QThpfZ