DSA-2024-008: Security Update for Dell XtremIO X2 Multiple Component Vulnerabilities
Summary: Dell XtremIO X2 remediation is available for multiple security vulnerabilities that could be exploited by malicious users to compromise the affected system.
Impact
Critical
Details
|
Third-party Component |
CVEs |
More Information |
||||||||
|---|---|---|---|---|---|---|---|---|---|---|
|
bind |
CVE-2023-2828, CVE-2023-3341 |
|||||||||
|
c-ares |
CVE-2023-32067 |
|||||||||
|
cyrus-sasl |
CVE-2022-24407 |
|||||||||
|
emacs |
CVE-2022-48339 |
|||||||||
|
gd |
CVE-2016-5766 |
|||||||||
|
gcc |
CVE-2021-42574 |
|||||||||
|
git |
CVE-2023-25652, CVE-2023-29007 |
|||||||||
|
gzip |
CVE-2022-1271 |
|||||||||
|
httpd |
CVE-2016-2161, CVE-2021-26691, CVE-2021-34798, CVE-2021-39275, CVE-2021-40438, CVE-2022-22720, CVE-2023-25690 |
RHSA-2017:0906 |
||||||||
|
kernel |
CVE-2023-35001, CVE-2023-35788, CVE-2023-3609, CVE-2023-3611, CVE-2023-3776, CVE-2023-4206, CVE-2023-4207, CVE-2023-4208, CVE-2023-42753, CVE-2023-4623, CVE-2024-1086, CVE-2023-4921, CVE-2020-36385, CVE-2020-0466, CVE-2022-0492, CVE-2022-0330, CVE-2021-3752, CVE-2022-32250, CVE-2022-1729, CVE-2022-42896, CVE-2022-3564, CVE-2022-22942, CVE-2023-32233, CVE-2022-4378, CVE-2020-0465, CVE-2021-0920, CVE-2020-36322, CVE-2022-42703, CVE-2020-25704 |
RHSA-2022:0063 |
||||||||
|
krb5-devel/krb5-libs |
CVE-2022-42898 |
|||||||||
|
libssh2 |
CVE-2020-22218 |
|||||||||
|
libXpm |
CVE-2022-4883 |
|||||||||
|
nss |
CVE-2021-43527, CVE-2023-0767 |
|||||||||
|
openldap |
CVE-2020-25709, CVE-2020-25710 |
|||||||||
|
openssh |
CVE-2023-38408 |
|||||||||
|
openssl |
CVE-2016-2183, CVE-2021-23840, CVE-2021-3712, CVE-2022-0778, CVE-2023-0286 |
RHSA-2018:2123 |
||||||||
|
open-vm-tools |
CVE-2022-31676, CVE-2023-20900, CVE-2023-34058, CVE-2023-34059 |
|||||||||
|
polkit |
CVE-2021-4034 |
|||||||||
|
python |
CVE-2023-24329, CVE-2020-26137, CVE-2020-26116 |
|||||||||
|
python-pillow |
CVE-2022-22817, CVE-2023-44271 |
|||||||||
|
rpm |
CVE-2021-20271 |
|||||||||
|
rsync |
CVE-2022-29154 |
|||||||||
|
rsyslog |
CVE-2022-24903 |
|||||||||
|
samba |
CVE-2022-38023, CVE-2020-25717, CVE-2016-2124 |
|||||||||
|
ssd |
CVE-2022-4254 |
|||||||||
|
sudo |
CVE-2023-22809 |
|||||||||
|
xz |
CVE-2022-1271 |
|||||||||
|
zlib |
CVE-2018-25032 |
|||||||||
Affected Products & Remediation
|
Product |
Software/Firmware |
Affected Versions |
Remediated Versions |
Link |
|---|---|---|---|---|
|
XtremIO X2 |
XMS |
Versions prior to 6.4.2-13 |
Version 6.4.2-13 or later |
https://dl.dell.com/downloads/P8R9D_XtremIO-6.4.2-&-XMS-6.4.2-(6.4.2-13_X2_XIOS_6.4.2-13_XMS).tar |
|
Product |
Software/Firmware |
Affected Versions |
Remediated Versions |
Link |
|---|---|---|---|---|
|
XtremIO X2 |
XMS |
Versions prior to 6.4.2-13 |
Version 6.4.2-13 or later |
https://dl.dell.com/downloads/P8R9D_XtremIO-6.4.2-&-XMS-6.4.2-(6.4.2-13_X2_XIOS_6.4.2-13_XMS).tar |
Revision History
| Revision | Date | Description |
|---|---|---|
| 1.0 | 2024-08-06 | Initial Release |
| 2.0 | 2024-08-06 | Updated for enhanced presentation with no changes to content. |