DSA-2019-035: Dell EMC Disk Library for mainframe Security Update for OpenSSL Vulnerability

This article applies to This article does not apply to This article is not tied to any specific product. Not all product versions are identified in this article.

Impact

Medium

Details

Summary:      
The OpenSSL library component within Dell EMC Disk Library for mainframe requires a security update to address the vulnerability  Simultaneous Multi-threading (SMT) in processors can enable local users to exploit software vulnerable to timing attacks via a side-channel timing attack on 'port contention'. 

The OpenSSL library component within Dell EMC Disk Library for mainframe requires a security update to address a vulnerability. The embedded component is updated for the following vulnerability:     

  • OpenSSL

           CVE-2018-5407

For more information about any of the Common Vulnerabilities and Exposures (CVEs) mentioned here, consult the National Vulnerability Database (NVD) at http://nvd.nist.gov/home.cfm.  

To search for a particular CVE, use the database s search utility at http://web.nvd.nist.gov/view/vuln/search.

The OpenSSL library component within Dell EMC Disk Library for mainframe requires a security update to address a vulnerability. The embedded component is updated for the following vulnerability:     

  • OpenSSL

           CVE-2018-5407

For more information about any of the Common Vulnerabilities and Exposures (CVEs) mentioned here, consult the National Vulnerability Database (NVD) at http://nvd.nist.gov/home.cfm.  

To search for a particular CVE, use the database s search utility at http://web.nvd.nist.gov/view/vuln/search.

Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.

Affected Products & Remediation

Affected products:      
Dell EMC Disk Library for mainframe DLm8100 and DLm2100 at 4.5.4p1 and earlier


Remediation:     
The following Dell EMC Disk Library for mainframe Security Update addresses this vulnerability:  

  • Dell EMC Disk Library for mainframe Security Update 4.5-4.2

Dell EMC recommends all customers upgrade at the earliest opportunity. Contact Dell EMC Disk Library for mainframe customer support to download the required dlm-security file and install it.


Link to Remedies:     
Dell EMC recommends all customers upgrade at the earliest opportunity.

Contact Dell EMC Disk Library for mainframe customer support to download the required dlm-security file and install it. 

This may require an upgrade to the current DLm software release.



Affected products:      
Dell EMC Disk Library for mainframe DLm8100 and DLm2100 at 4.5.4p1 and earlier


Remediation:     
The following Dell EMC Disk Library for mainframe Security Update addresses this vulnerability:  

  • Dell EMC Disk Library for mainframe Security Update 4.5-4.2

Dell EMC recommends all customers upgrade at the earliest opportunity. Contact Dell EMC Disk Library for mainframe customer support to download the required dlm-security file and install it.


Link to Remedies:     
Dell EMC recommends all customers upgrade at the earliest opportunity.

Contact Dell EMC Disk Library for mainframe customer support to download the required dlm-security file and install it. 

This may require an upgrade to the current DLm software release.



Related Information

Affected Products

Disk Library for mainframe

Products

Disk Library for mainframe, Disk Library for mainframe DLm2100, Disk Library for mainframe DLm8100, Product Security Information
Article Properties
Article Number: 000001838
Article Type: Dell Security Advisory
Last Modified: 20 Sep 2024
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.