SB2018121206 - Multiple vulnerabilities in IBM AIX
Published: December 12, 2018
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 3 secuirty vulnerabilities.
1) Information disclosure (CVE-ID: CVE-2018-0734)
The vulnerability allows a local attacker to obtain potentially sensitive information.
The vulnerability exists due to unspecified flaw in Digital Signature Algorithm (DSA). A local attacker can conduct a timing side-channel attack and recover the private key, which could be used to conduct further attacks.
2) Side-channel attack (CVE-ID: CVE-2018-5407)
The vulnerability allows a physical attacker to obtain potentially sensitive information.
The vulnerability exists due to due to execution of engine sharing on SMT (e.g.Hyper-Threading) architectures when improper handling of information by the processor. A physical attacker can construct a timing side channel to hijack information from processes that are running in the same core.
Note: the vulnerability has been dubbed as PortSmash microarchitecture bug.
3) Privilege escalation (CVE-ID: CVE-2018-14665)
The vulnerability allows a local user to gain elevated privileges on the target system.
The vulnerability exists due to improper handling of two command-line options, namely -logfile and -modulepath. A local user can specify a '-modulepath' argument with an insecure path to create, overwrite or delete any files with root privileges.
Remediation
Install update from vendor's website.