DSA-2019-035: Dell EMC Disk Library for mainframe Security Update for OpenSSL Vulnerability
Impact
Medium
Details
Summary:
The OpenSSL library component within Dell EMC Disk Library for mainframe requires a security update to address the vulnerability Simultaneous Multi-threading (SMT) in processors can enable local users to exploit software vulnerable to timing attacks via a side-channel timing attack on 'port contention'.
The OpenSSL library component within Dell EMC Disk Library for mainframe requires a security update to address a vulnerability. The embedded component is updated for the following vulnerability:
-
OpenSSL
CVE-2018-5407
For more information about any of the Common Vulnerabilities and Exposures (CVEs) mentioned here, consult the National Vulnerability Database (NVD) at http://nvd.nist.gov/home.cfm.
To search for a particular CVE, use the database s search utility at http://web.nvd.nist.gov/view/vuln/search.
The OpenSSL library component within Dell EMC Disk Library for mainframe requires a security update to address a vulnerability. The embedded component is updated for the following vulnerability:
-
OpenSSL
CVE-2018-5407
For more information about any of the Common Vulnerabilities and Exposures (CVEs) mentioned here, consult the National Vulnerability Database (NVD) at http://nvd.nist.gov/home.cfm.
To search for a particular CVE, use the database s search utility at http://web.nvd.nist.gov/view/vuln/search.
Affected Products & Remediation
Affected products:
Dell EMC Disk Library for mainframe DLm8100 and DLm2100 at 4.5.4p1 and earlier
Remediation:
The following Dell EMC Disk Library for mainframe Security Update addresses this vulnerability:
-
Dell EMC Disk Library for mainframe Security Update 4.5-4.2
Dell EMC recommends all customers upgrade at the earliest opportunity. Contact Dell EMC Disk Library for mainframe customer support to download the required dlm-security file and install it.
Link to Remedies:
Dell EMC recommends all customers upgrade at the earliest opportunity.
Contact Dell EMC Disk Library for mainframe customer support to download the required dlm-security file and install it.
This may require an upgrade to the current DLm software release.
Affected products:
Dell EMC Disk Library for mainframe DLm8100 and DLm2100 at 4.5.4p1 and earlier
Remediation:
The following Dell EMC Disk Library for mainframe Security Update addresses this vulnerability:
-
Dell EMC Disk Library for mainframe Security Update 4.5-4.2
Dell EMC recommends all customers upgrade at the earliest opportunity. Contact Dell EMC Disk Library for mainframe customer support to download the required dlm-security file and install it.
Link to Remedies:
Dell EMC recommends all customers upgrade at the earliest opportunity.
Contact Dell EMC Disk Library for mainframe customer support to download the required dlm-security file and install it.
This may require an upgrade to the current DLm software release.