SB2017050854 - IBM Flex System Chassis Management Module (CMM) update for GNU C Library



SB2017050854 - IBM Flex System Chassis Management Module (CMM) update for GNU C Library

Published: May 8, 2017 Updated: February 21, 2025

Security Bulletin ID SB2017050854
Severity
High
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Use-after-free error (CVE-ID: CVE-2017-12133)

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The weakness exists in the DNS stub resolver due to it will solicit large UDP responses from name servers, potentially simplifying off-path DNS spoofing attackers due to IP fragmentation when enabling EDNS support. A remote attacker can trigger use after free and execute arbitrary code.

Successful exploitation of the vulnerability may result in system compromise.

Remediation

Install update from vendor's website.