SB2017050829 - Input validation error in IBM Integrated Management Module II (IMM2) for System x, Flex and BladeCenter systems 



SB2017050829 - Input validation error in IBM Integrated Management Module II (IMM2) for System x, Flex and BladeCenter systems

Published: May 8, 2017 Updated: July 20, 2023

Security Bulletin ID SB2017050829
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Adjecent network
Highest impact Denial of service

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Input validation error (CVE-ID: CVE-2015-8605)

The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.

ISC DHCP 4.x before 4.1-ESV-R12-P1, 4.2.x, and 4.3.x before 4.3.3-P1 allows remote attackers to cause a denial of service (application crash) via an invalid length field in a UDP IPv4 packet.


Remediation

Install update from vendor's website.