DSA-2024-191: Security Update for Dell Enterprise SONiC Distribution Vulnerabilities
Resumo: Dell Enterprise SONiC remediation is available for multiple security vulnerabilities that could be exploited by malicious users to compromise the affected system.
Este artigo aplica-se a
Este artigo não se aplica a
Este artigo não está vinculado a nenhum produto específico.
Nem todas as versões do produto estão identificadas neste artigo.
Impacto
High
Dados
| Third-party Component | CVEs | More Information |
|---|---|---|
| curl | CVE-2023-27534, CVE-2023-28321, CVE-2023-28322, CVE-2023-38546, CVE-2023-46218 | See NVD link below for individual scores for each CVE. http://nvd.nist.gov/ |
| dbus | CVE-2023-34969 | See NVD link below for individual scores for each CVE. http://nvd.nist.gov/ |
| grub2 | CVE-2023-4692, CVE-2023-4693 | See NVD link below for individual scores for each CVE. http://nvd.nist.gov/ |
| libgnutls30 (gnutls28) | CVE-2023-5981, CVE-2024-0553 | See NVD link below for individual scores for each CVE. http://nvd.nist.gov/ |
| libisc-export1100 (bind9) | CVE-2023-3341 | See NVD link below for individual scores for each CVE. http://nvd.nist.gov/ |
| libkrb5-3 (krb5) | CVE-2023-36054 | See NVD link below for individual scores for each CVE. http://nvd.nist.gov/ |
| libnghttp2-14 (nghttp2) | CVE-2020-11080, CVE-2023-44487 | See NVD link below for individual scores for each CVE. http://nvd.nist.gov/ |
| libx11 | CVE-2023-43785, CVE-2023-43786, CVE-2023-43787 | See NVD link below for individual scores for each CVE. http://nvd.nist.gov/ |
| libxpm4 | CVE-2023-43788, CVE-2023-43789 | See NVD link below for individual scores for each CVE. http://nvd.nist.gov/ |
| ncurses | CVE-2023-29491, CVE-2021-39537 | See NVD link below for individual scores for each CVE. http://nvd.nist.gov/ |
| openssh | CVE-2021-41617, CVE-2023-48795, CVE-2023-51385 | See NVD link below for individual scores for each CVE. http://nvd.nist.gov/ |
| python2.7 | CVE-2024-0450 | See NVD link below for individual scores for each CVE. http://nvd.nist.gov/ |
| python3.7 | CVE-2023-40217, CVE-2022-48560, CVE-2022-48564, CVE-2022-48565, CVE-2022-48566, CVE-2023-6597, CVE-2024-0450 | See NVD link below for individual scores for each CVE. http://nvd.nist.gov/ |
| sudo-ldap (sudo) | CVE-2023-28486, CVE-2023-28487, CVE-2023-7090 | See NVD link below for individual scores for each CVE. http://nvd.nist.gov/ |
| tar | CVE-2023-39804 | See NVD link below for individual scores for each CVE. http://nvd.nist.gov/ |
Produtos afetados e soluções
| Product | Affected Versions | Remediated Versions | Link |
|---|---|---|---|
| Enterprise SONiC Distribution | Versions prior to 4.2.1 | 4.2.1 | Enterprise SONiC OS 4.2.1 |
| Product | Affected Versions | Remediated Versions | Link |
|---|---|---|---|
| Enterprise SONiC Distribution | Versions prior to 4.2.1 | 4.2.1 | Enterprise SONiC OS 4.2.1 |
Histórico de revisão
| Revision | Date | Description |
|---|---|---|
| 1.0 | 2024-05-02 | Initial release |
Informações relacionadas
Aviso de isenção legal
Produtos afetados
Enterprise SONiC DistributionPropriedades do artigo
Número do artigo: 000224731
Tipo de artigo: Dell Security Advisory
Último modificado: 02 mai. 2024
Encontre as respostas de outros usuários da Dell para suas perguntas.
Serviços de suporte
Verifique se o dispositivo está coberto pelos serviços de suporte.