DSA-2019-126: Dell EMC ESRS Virtual Edition Security Update for Multiple Third Party Component Vulnerabilities
This article applies to
This article does not apply to
This article is not tied to any specific product.
Not all product versions are identified in this article.
Impact
Critical
Details
Summary:
Multiple components within Dell EMC ESRS Virtual Edition require a security update to address various vulnerabilities.
The components are updated to address the following vulnerabilities:
For more information about any of the Common Vulnerabilities and Exposures (CVEs) mentioned here, consult the National Vulnerability Database (NVD) at http://nvd.nist.gov/home.cfm. To search for a particular CVE, use the database s search utility at http://web.nvd.nist.gov/view/vuln/search.
- JRE: CVE-2018-3136, CVE-2018-3139, CVE-2018-3149, CVE-2018-3150, CVE-2018-3157, CVE-2018-3169, CVE-2018-3180, CVE-2018-3183, CVE-2018-3209, CVE-2018-3211, CVE-2018-3214, CVE-2018-13785, CVE-2019-2602, CVE-2019-2684, CVE-2019-2697, CVE-2019-2698, CVE-2019-2699
- Python: CVE-2019-9636, CVE-2019-9948
- Kernel: CVE-2018-12126, CVE-2018-12127, CVE-2018-12130, CVE-2019-11091, CVE-2019-11477, CVE-2019-11478, CVE-2019-11479
For more information about any of the Common Vulnerabilities and Exposures (CVEs) mentioned here, consult the National Vulnerability Database (NVD) at http://nvd.nist.gov/home.cfm. To search for a particular CVE, use the database s search utility at http://web.nvd.nist.gov/view/vuln/search.
The components are updated to address the following vulnerabilities:
For more information about any of the Common Vulnerabilities and Exposures (CVEs) mentioned here, consult the National Vulnerability Database (NVD) at http://nvd.nist.gov/home.cfm. To search for a particular CVE, use the database s search utility at http://web.nvd.nist.gov/view/vuln/search.
- JRE: CVE-2018-3136, CVE-2018-3139, CVE-2018-3149, CVE-2018-3150, CVE-2018-3157, CVE-2018-3169, CVE-2018-3180, CVE-2018-3183, CVE-2018-3209, CVE-2018-3211, CVE-2018-3214, CVE-2018-13785, CVE-2019-2602, CVE-2019-2684, CVE-2019-2697, CVE-2019-2698, CVE-2019-2699
- Python: CVE-2019-9636, CVE-2019-9948
- Kernel: CVE-2018-12126, CVE-2018-12127, CVE-2018-12130, CVE-2019-11091, CVE-2019-11477, CVE-2019-11478, CVE-2019-11479
For more information about any of the Common Vulnerabilities and Exposures (CVEs) mentioned here, consult the National Vulnerability Database (NVD) at http://nvd.nist.gov/home.cfm. To search for a particular CVE, use the database s search utility at http://web.nvd.nist.gov/view/vuln/search.
Affected Products & Remediation
Affected products:
Dell EMC ESRS Virtual Edition versions prior to 3.38.00.12.
Remediation:
The following Dell EMC ESRS Virtual Edition release contains a resolution to this vulnerability:
Dell EMC recommends all customers upgrade at the earliest opportunity. Contact Dell EMC ESRS Virtual Edition customer support to download the required rpm file and install it.
The ESRS VE patch is published in ESRS vLM (Virtual Life cycle Management) repository and the existing process triggers an Email notification to customer s ESRS VE primary & secondary contacts. Email notification contains a link to Release notes (along with details of security updates) and a link to update the customer s VE to the latest patch. Contact Dell EMC ESRS Virtual Edition Customer Support for any questions regarding upgrading your Dell EMC ESRS Virtual Edition system.
Dell EMC ESRS Virtual Edition versions prior to 3.38.00.12.
Remediation:
The following Dell EMC ESRS Virtual Edition release contains a resolution to this vulnerability:
- Dell EMC ESRS VE version 3.38.00.12
Dell EMC recommends all customers upgrade at the earliest opportunity. Contact Dell EMC ESRS Virtual Edition customer support to download the required rpm file and install it.
The ESRS VE patch is published in ESRS vLM (Virtual Life cycle Management) repository and the existing process triggers an Email notification to customer s ESRS VE primary & secondary contacts. Email notification contains a link to Release notes (along with details of security updates) and a link to update the customer s VE to the latest patch. Contact Dell EMC ESRS Virtual Edition Customer Support for any questions regarding upgrading your Dell EMC ESRS Virtual Edition system.
Affected products:
Dell EMC ESRS Virtual Edition versions prior to 3.38.00.12.
Remediation:
The following Dell EMC ESRS Virtual Edition release contains a resolution to this vulnerability:
Dell EMC recommends all customers upgrade at the earliest opportunity. Contact Dell EMC ESRS Virtual Edition customer support to download the required rpm file and install it.
The ESRS VE patch is published in ESRS vLM (Virtual Life cycle Management) repository and the existing process triggers an Email notification to customer s ESRS VE primary & secondary contacts. Email notification contains a link to Release notes (along with details of security updates) and a link to update the customer s VE to the latest patch. Contact Dell EMC ESRS Virtual Edition Customer Support for any questions regarding upgrading your Dell EMC ESRS Virtual Edition system.
Dell EMC ESRS Virtual Edition versions prior to 3.38.00.12.
Remediation:
The following Dell EMC ESRS Virtual Edition release contains a resolution to this vulnerability:
- Dell EMC ESRS VE version 3.38.00.12
Dell EMC recommends all customers upgrade at the earliest opportunity. Contact Dell EMC ESRS Virtual Edition customer support to download the required rpm file and install it.
The ESRS VE patch is published in ESRS vLM (Virtual Life cycle Management) repository and the existing process triggers an Email notification to customer s ESRS VE primary & secondary contacts. Email notification contains a link to Release notes (along with details of security updates) and a link to update the customer s VE to the latest patch. Contact Dell EMC ESRS Virtual Edition Customer Support for any questions regarding upgrading your Dell EMC ESRS Virtual Edition system.
Related Information
Legal Disclaimer
Affected Products
Secure Remote Services Virtual EditionProducts
Secure Remote Services Virtual Edition, Product Security InformationArticle Properties
Article Number: 000153801
Article Type: Dell Security Advisory
Last Modified: 22 May 2021
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.