IBM OS/400 OpenSSL DER Format Data Processing Vulnerability

by Carol~ Moderator - 5/7/12 10:45 AM

In Reply to: VULNERABILITIES / FIXES - May 07, 2012 by Carol~ Moderator

Release Date : 2012-05-07

Criticality level : Highly critical
Impact : DoS
System access
Where : From remote
Solution Status : Vendor Patch

Operating System: IBM OS/400 6.x

Description:
IBM has acknowledged a vulnerability in OS/400, which can be exploited by malicious people to potentially compromise an application using the library.

The vulnerability is reported in version V6R1M0.

Solution:
Apply patch 5733SC1.

Original Advisory:
IBM (SE51936):
http://www-01.ibm.com/support/docview.wss?uid=nas2d7439844d1fd14f0862579f5003c71ce

http://secunia.com/advisories/49107/