DSA-2019-159: Dell EMC Data Computing Appliance (DCA) Security Update for Multiple Third Party Components

이 문서는 다음에 적용됩니다. 이 문서는 다음에 적용되지 않습니다. 이 문서는 특정 제품과 관련이 없습니다. 모든 제품 버전이 이 문서에 나와 있는 것은 아닙니다.

영향

Critical

세부 정보

Summary:   
Multiple components within Dell EMC DCA require a security update to address various vulnerabilities. 

The components are updated for the following vulnerabilities:   

  • Kernel

CVE-2017-17805    CVE-2018-17972    CVE-2019-1125    CVE-2019-5489

  • bind

CVE-2018-5743

  • vim

CVE-2019-12735

  • libssh2

CVE-2019-3855    CVE-2019-3856    CVE-2019-3857    CVE-2019-3863

  • OpenJDK

CVE-2019-2745    CVE-2019-2762    CVE-2019-2769    CVE-2019-2786
CVE-2019-2816    CVE-2019-2842                                                

  • OpenSSH

CVE-2018-15473

  • Python

CVE-2019-9636

  • OpenSSL

CVE-2019-1559

For more information about any of the Common Vulnerabilities and Exposures (CVEs) mentioned here, consult the National Vulnerability Database (NVD) at http://nvd.nist.gov/home.cfm.

To search for a particular CVE, use the database s search utility at http://web.nvd.nist.gov/view/vuln/search.

The components are updated for the following vulnerabilities:   

  • Kernel

CVE-2017-17805    CVE-2018-17972    CVE-2019-1125    CVE-2019-5489

  • bind

CVE-2018-5743

  • vim

CVE-2019-12735

  • libssh2

CVE-2019-3855    CVE-2019-3856    CVE-2019-3857    CVE-2019-3863

  • OpenJDK

CVE-2019-2745    CVE-2019-2762    CVE-2019-2769    CVE-2019-2786
CVE-2019-2816    CVE-2019-2842                                                

  • OpenSSH

CVE-2018-15473

  • Python

CVE-2019-9636

  • OpenSSL

CVE-2019-1559

For more information about any of the Common Vulnerabilities and Exposures (CVEs) mentioned here, consult the National Vulnerability Database (NVD) at http://nvd.nist.gov/home.cfm.

To search for a particular CVE, use the database s search utility at http://web.nvd.nist.gov/view/vuln/search.

Dell Technologies는 모든 고객이 CVSS 기본 점수와 관련 임시 및 환경 점수를 모두 고려할 것을 권장합니다. 이 경우 특정 보안 취약성과 관련된 잠재적인 심각도에 영향을 미칠 수 있습니다.

영향을 받는 제품 및 문제 해결

Affected products:     
Dell EMC Data Computing Appliance (DCA) software versions prior to 3.5.4.0


Remediation:     
The following Dell EMC DCA release addresses these vulnerabilities:     

  • Dell EMC DCA 3.5.4.0

For Dell EMC DCA software version 3.3.0.0, 3.4.0.0, 3.4.1.0, 3.4.2.0, 3.5.0.0, 3.5.1.0, 3.5.2.0, and 3.5.3.0, the security update is contained in release 3.5.4.0.

To upgrade an earlier DCA version, you must upgrade to version 3.3.0.0 and then to version 3.5.4.0.

Dell EMC recommends all customers upgrade at the earliest opportunity. Contact Dell EMC DCA customer support to download the required rpm file and install it.



Affected products:     
Dell EMC Data Computing Appliance (DCA) software versions prior to 3.5.4.0


Remediation:     
The following Dell EMC DCA release addresses these vulnerabilities:     

  • Dell EMC DCA 3.5.4.0

For Dell EMC DCA software version 3.3.0.0, 3.4.0.0, 3.4.1.0, 3.4.2.0, 3.5.0.0, 3.5.1.0, 3.5.2.0, and 3.5.3.0, the security update is contained in release 3.5.4.0.

To upgrade an earlier DCA version, you must upgrade to version 3.3.0.0 and then to version 3.5.4.0.

Dell EMC recommends all customers upgrade at the earliest opportunity. Contact Dell EMC DCA customer support to download the required rpm file and install it.



관련 정보

해당 제품

Data Computing Appliance V3

제품

Data Computing Appliance V3, Product Security Information
문서 속성
문서 번호: 000001849
문서 유형: Dell Security Advisory
마지막 수정 시간: 20 9월 2024
다른 Dell 사용자에게 질문에 대한 답변 찾기
지원 서비스
디바이스에 지원 서비스가 적용되는지 확인하십시오.