SB202502197144 - Multiple vulnerabilities in IBM Dynamic System Analysis (DSA) Preboot
Published: October 31, 2018 Updated: February 19, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 secuirty vulnerabilities.
1) Memory corruption (CVE-ID: CVE-2018-14622)
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The vulnerability exists due to boundary error when checking the return value of the makefd_xprt() function, as defined in the svc_vc.csource code. A remote attacker can flood a targeted system with new connections, exhaust the maximum number of available file descriptors, trigger NULL pointer dereference and cause the affected software to terminate abnormally.
2) Infinite loop (CVE-ID: CVE-2018-14621)
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The vulnerability exists due to improper handling of port settings. A remote attacker can configure the role of the targeted port to poll, rather than select, trigger infinite loop and cause the service to crash.
Remediation
Install update from vendor's website.