DSA-2019-114: Dell EMC Unisphere Central Security Update for Multiple Embedded Component Vulnerabilities

本文适用于 本文不适用于 本文并非针对某种特定的产品。 本文并非包含所有产品版本。

影响

Critical

详情

Summary:      
Multiple embedded components within Dell EMC Unisphere Central require security updates to address various vulnerabilities.

The embedded components have been updated to remediate the following vulnerabilities:      

  • curl

CVE-2016-7167    CVE-2016-8615    CVE-2016-8616    CVE-2016-8617
CVE-2016-8618    CVE-2016-8619    CVE-2016-8620    CVE-2016-8621
CVE-2016-8622    CVE-2016-8623    CVE-2016-8624    CVE-2016-9586
CVE-2017-7407    CVE-2017-1000100    CVE-2017-1000254    CVE-2018-1000007
CVE-2018-1000120    CVE-2018-1000121    CVE-2018-1000122    CVE-2018-1000301
CVE-2018-14618        CVE-2018-16840        CVE-2018-16842

  • glibc

CVE-2015-5180      CVE-2017-12133    CVE-2017-15670    CVE-2017-15671
CVE-2017-15804    CVE-2018-11236

  • OpenSSL

CVE-2017-0739

For more information about the Common Vulnerability and Exposure (CVE) mentioned here, consult the National Vulnerability Database (NVD) at http://nvd.nist.gov/home.cfm.

To search for a particular CVE, use the database s search utility at http://web.nvd.nist.gov/view/vuln/search.

The embedded components have been updated to remediate the following vulnerabilities:      

  • curl

CVE-2016-7167    CVE-2016-8615    CVE-2016-8616    CVE-2016-8617
CVE-2016-8618    CVE-2016-8619    CVE-2016-8620    CVE-2016-8621
CVE-2016-8622    CVE-2016-8623    CVE-2016-8624    CVE-2016-9586
CVE-2017-7407    CVE-2017-1000100    CVE-2017-1000254    CVE-2018-1000007
CVE-2018-1000120    CVE-2018-1000121    CVE-2018-1000122    CVE-2018-1000301
CVE-2018-14618        CVE-2018-16840        CVE-2018-16842

  • glibc

CVE-2015-5180      CVE-2017-12133    CVE-2017-15670    CVE-2017-15671
CVE-2017-15804    CVE-2018-11236

  • OpenSSL

CVE-2017-0739

For more information about the Common Vulnerability and Exposure (CVE) mentioned here, consult the National Vulnerability Database (NVD) at http://nvd.nist.gov/home.cfm.

To search for a particular CVE, use the database s search utility at http://web.nvd.nist.gov/view/vuln/search.

Dell Technologies 建议所有客户考虑 CVSS 基本分数以及任何相关的时间和环境分数,这可能会影响与特定安全漏洞相关的潜在严重程度。

受影响的产品和补救措施

Affected products:      
Dell EMC Unisphere Central versions prior to 4.0.8.23220


Remediation:       
The following Dell EMC Unisphere Central release addresses these vulnerabilities:      

  • Dell EMC Unisphere Central 4.0.8.23220 (4.0 SP8)

Dell EMC recommends all customers upgrade at the earliest opportunity.


Link to Remedies:       
Registered Dell EMC Support customers can download Unisphere Central software from the Dell EMC Online Support web site at: https://support.emc.com/downloads/28224_Unisphere-Central 



Affected products:      
Dell EMC Unisphere Central versions prior to 4.0.8.23220


Remediation:       
The following Dell EMC Unisphere Central release addresses these vulnerabilities:      

  • Dell EMC Unisphere Central 4.0.8.23220 (4.0 SP8)

Dell EMC recommends all customers upgrade at the earliest opportunity.


Link to Remedies:       
Registered Dell EMC Support customers can download Unisphere Central software from the Dell EMC Online Support web site at: https://support.emc.com/downloads/28224_Unisphere-Central 



相关信息

受影响的产品

Unisphere Central

产品

Product Security Information, Unisphere Central
文章属性
文章编号: 000153792
文章类型: Dell Security Advisory
上次修改时间: 22 5月 2021
从其他戴尔用户那里查找问题的答案
支持服务
检查您的设备是否在支持服务涵盖的范围内。