lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  PHC 
Open Source and information security mailing list archives
Hash Suite for Android: free password hash cracker in your pocket
[<prev] [next>] [day] [month] [year] [list]
Date: Mon, 20 Nov 2017 18:07:35 +0000
From: EMC Product Security Response Center <>
To: "" <>
Subject: [FD] ESA-2017-094: EMC ScaleIO Multiple Vulnerabilities

Hash: SHA256

ESA-2017-094: EMC ScaleIO Multiple Vulnerabilities

EMC Identifier:  ESA-2017-094

CVE Identifier:  CVE-2017-8001, CVE-2017-8019, CVE-2017-8020

Severity Rating: CVSSv3 Base Score:  See below for CVSS scores for individual CVEs

Affected products:  
EMC ScaleIO 2.0.1.x version family (,,, 2.0.1)

EMC ScaleIO contains a number of vulnerabilities which could potentially be exploited by malicious users to compromise an affected system. 

EMC ScaleIO contains the following vulnerabilities:

*	Sensitive Information Disclosure (CVE-2017-8001)
In a Linux environment, one of the EMC ScaleIO support scripts saves the credentials of the ScaleIO MDM user who executed the script in clear text in temporary log files. The temporary files may potentially be read by an unprivileged user with access to the server where the script was executed to recover exposed credentials. 

CVSSv3 Base Score: 7.8 (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)

*	Denial of Service (CVE-2017-8019)
A vulnerability in ScaleIO message parsers (MDM,SDS, and LIA) could potentially allow an unauthenticated remote attacker to send specifically crafted packets to stop ScaleIO services and cause denial of service situation .

CVSSv3 Base Score: 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

*	ScaleIO Debugging (SDBG)  Service  Buffer Overflow CVE-2017-8020)
A buffer overflow vulnerability in ScaleIO SDBG service may potentially allow a remote unauthenticated attacker to execute arbitrary commands with root privileges on affected server. 

CVSSv3 Base Score: 8.1 (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)

The following EMC ScaleIO release contains resolution to these vulnerabilities:
*	EMC ScaleIO version

For CVE-2017-8001, EMC recommends all customers follow additional steps documented in knowledgebase article 503560. 

Link to remedies:
Customers can download software from 

EMC would like to thank David Berard, from Ubisoft Security & Risk Management team, for reporting these vulnerabilities.
Version: GnuPG v2


Sent through the Full Disclosure mailing list
Web Archives & RSS:

Powered by blists - more mailing lists