DSA-2020-179: Dell EMC Data Domain Security Update for OpenSSL Vulnerabilities
Resumen: The OpenSSL component within Dell EMC Data Domain requires a security update to address various vulnerabilities.
Impacto
Medium
Detalles
| Third-party Component | CVE(s) | More information |
| OpenSSL | CVE-2019-1547 | See NVD (http://nvd.nist.gov/) for individual scores for each CVE. |
| CVE-2019-1551 | ||
| CVE-2019-1563 | ||
| CVE-2019-1552 |
Data Domain upgraded to OpenSSL 1.0.2u to mitigate the above CVEs.
For more information about any of the Common Vulnerabilities and Exposures (CVEs) mentioned here, consult the National Vulnerability Database (NVD) at http://nvd.nist.gov/home.cfm.
To search for a particular CVE, use the database s search utility at http://web.nvd.nist.gov/view/vuln/search.
| Third-party Component | CVE(s) | More information |
| OpenSSL | CVE-2019-1547 | See NVD (http://nvd.nist.gov/) for individual scores for each CVE. |
| CVE-2019-1551 | ||
| CVE-2019-1563 | ||
| CVE-2019-1552 |
Data Domain upgraded to OpenSSL 1.0.2u to mitigate the above CVEs.
For more information about any of the Common Vulnerabilities and Exposures (CVEs) mentioned here, consult the National Vulnerability Database (NVD) at http://nvd.nist.gov/home.cfm.
To search for a particular CVE, use the database s search utility at http://web.nvd.nist.gov/view/vuln/search.
Corrección y productos afectados
Affected products:
All Data Domain physical and virtual models
Dell EMC Data Domain OS versions prior to DDOS 6.0.2.9
Dell EMC Data Domain OS versions prior to DDOS 6.1.2.70
Dell EMC Data Domain OS versions prior to DDOS 6.2.1.0
Dell EMC Data Domain OS versions prior to DDOS 7.0.0.20
Remediation:
The following Dell EMC Data Domain releases address these vulnerabilities:
-
Dell EMC Data Domain OS versions DDOS 6.1.2.70 and later
-
Dell EMC Data Domain OS versions DDOS 6.2.1.0 and later
-
Dell EMC Data Domain OS versions DDOS 7.0.0.20 and later
Dell EMC recommends all customers upgrade at the earliest opportunity.
Affected products:
All Data Domain physical and virtual models
Dell EMC Data Domain OS versions prior to DDOS 6.0.2.9
Dell EMC Data Domain OS versions prior to DDOS 6.1.2.70
Dell EMC Data Domain OS versions prior to DDOS 6.2.1.0
Dell EMC Data Domain OS versions prior to DDOS 7.0.0.20
Remediation:
The following Dell EMC Data Domain releases address these vulnerabilities:
-
Dell EMC Data Domain OS versions DDOS 6.1.2.70 and later
-
Dell EMC Data Domain OS versions DDOS 6.2.1.0 and later
-
Dell EMC Data Domain OS versions DDOS 7.0.0.20 and later
Dell EMC recommends all customers upgrade at the earliest opportunity.
Soluciones alternativas y mitigaciones
None