ESB-2019.1088 - [Win][Linux] IBM Watson Explorer: Multiple vulnerabilities 2019-04-01

Printable version
PGP/GPG verifiable version

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

===========================================================================
             AUSCERT External Security Bulletin Redistribution

                               ESB-2019.1088
              Multiple vulnerabilities affect Watson Explorer
             (CVE-2017-14166, CVE-2017-14501, CVE-2017-14502,
                              CVE-2017-14503)
                               1 April 2019

===========================================================================

        AusCERT Security Bulletin Summary
        ---------------------------------

Product:           IBM Watson Explorer
Publisher:         IBM
Operating System:  Linux variants
                   Windows
Impact/Access:     Execute Arbitrary Code/Commands -- Remote with User Interaction
                   Denial of Service               -- Remote with User Interaction
Resolution:        Patch/Upgrade
CVE Names:         CVE-2017-14503 CVE-2017-14502 CVE-2017-14501
                   CVE-2017-14166  

Reference:         ESB-2019.0025
                   ESB-2018.3719
                   ESB-2018.3506.2
                   ESB-2018.3393
                   ESB-2018.2319

Original Bulletin: 
   http://www.ibm.com/support/docview.wss?uid=ibm10878841

- --------------------------BEGIN INCLUDED TEXT--------------------

Security Bulletin: Multiple vulnerabilities affect Watson Explorer
(CVE-2017-14166, CVE-2017-14501, CVE-2017-14502, CVE-2017-14503)

Document information

More support for: Watson Explorer

Software version: 10.0.0, 11.0.0, 11.0.1, 11.0.2, 12.0.0, 12.0.1

Operating system(s): Linux, Windows

Reference #: 0878841

Modified date: 29 March 2019

Summary

Multiple libarchive vulnerabilities affect Watson Explorer.

Vulnerability Details

CVEID: CVE-2017-14166
DESCRIPTION: libarchive is vulnerable to a denial of service, caused by a
xml_data heap-based buffer over-read issue in the atol8 function in
archive_read_support_format_xar.c. By persuading a victim to open a
specially-crafted file, a remote attacker could exploit this vulnerability to
cause the application to crash.
CVSS Base Score: 5.5
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/
131555 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)

CVEID: CVE-2017-14501
DESCRIPTION: libarchive is vulnerable to a heap-based buffer overflow, caused
by improper bounds checking by the parse_file_info function in
archive_read_support_format_iso9660.c. By persuading a victim to extract a
specially-crafted iso file, a remote attacker could overflow a buffer and
execute arbitrary code on the system.
CVSS Base Score: 7.8
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/
132122 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)

CVEID: CVE-2017-14502
DESCRIPTION: libarchive is vulnerable to a buffer overflow, caused by improper
bounds checking by the read_header function in
archive_read_support_format_rar.c. By persuading a victim to open a
specially-crafted RAR file, a remote attacker could overflow a buffer and
execute arbitrary code on the system.
CVSS Base Score: 7.8
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/
132123 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)

CVEID: CVE-2017-14503
DESCRIPTION: libarchive is vulnerable to a heap-based buffer overflow, caused
by improper bounds checking by the lha_read_data_none function in
archive_read_support_format_lha.c. By persuading a victim to extract a
specially-crafted lha archive, a remote attacker could overflow a buffer and
execute arbitrary code on the system.
CVSS Base Score: 7.8
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/
132124 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)

Affected Products and Versions

These vulnerabilities apply to the following products and versions:

  o Watson Explorer Foundational Components version 10.0.0.5 and earlier.
  o Watson Explorer Foundational Components version 11.0.0.3 and earlier,
    version 11.0.1, version 11.0.2.
  o Watson Explorer Foundational Components version 12.0.1 and earlier.

Remediation/Fixes

Follow these steps to upgrade to the required version of libarchive. The table
reflects product names at the time the specified versions were released. To
use the link to Fix Central in this table, you must first log in to the IBM
Support: Fix Central site at http://www.ibm.com/support/fixcentral/.
 

+---------------------+-------------+----------------------------------------+
|                     |Affected     |                                        |
|  Affected Product   |Versions     |    How to acquire and apply the fix    |
+---------------------+-------------+----------------------------------------+
|                     |             |Upgrade to Version 12.0.2 or later.     |
|IBM Watson Explorer  |12.0.0,      |                                        |
|DAE Foundational     |12.0.1       |See  Watson Explorer Version 12.0.2.2   |
|Components           |             |Foundational Components for download    |
|                     |             |information and instructions.           |
+---------------------+-------------+----------------------------------------+
|IBM Watson Explorer  |11.0.0.0 -   |Upgrade to Version 11.0.2.4 or later.   |
|Foundational         |11.0.0.3,    |                                        |
|Components           |11.0.1,      |See Watson Explorer Version 11.0.2.5    |
|                     |11.0.2 -     |Foundational Components for download    |
|                     |11.0.2.3     |information and instructions.           |
+---------------------+-------------+----------------------------------------+
|                     |             |Upgrade to 10.0.0.6.                    |
|IBM Watson Explorer  |10.0.0.0 -   |                                        |
|Foundational         |10.0.0.5     |See Watson Explorer Version 10.0.0.6    |
|Components           |             |Foundational Components for download    |
|                     |             |information and instructions.           |
+---------------------+-------------+----------------------------------------+

Change History

29 March 2019 : Original version published

*The CVSS Environment Score is customer environment specific and will
ultimately impact the Overall CVSS Score. Customers can evaluate the impact of
this vulnerability in their environments by accessing the links in the
Reference section of this Security Bulletin.

Disclaimer

According to the Forum of Incident Response and Security Teams (FIRST), the
Common Vulnerability Scoring System (CVSS) is an "industry open standard
designed to convey vulnerability severity and help to determine urgency and
priority of response." IBM PROVIDES THE CVSS SCORES ""AS IS"" WITHOUT WARRANTY
OF ANY KIND, INCLUDING THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS
FOR A PARTICULAR PURPOSE. CUSTOMERS ARE RESPONSIBLE FOR ASSESSING THE IMPACT
OF ANY ACTUAL OR POTENTIAL SECURITY VULNERABILITY.

- --------------------------END INCLUDED TEXT--------------------

You have received this e-mail bulletin as a result of your organisation's
registration with AusCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.

NOTE: Third Party Rights
This security bulletin is provided as a service to AusCERT's members.  As
AusCERT did not write the document quoted above, AusCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AusCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.

NOTE: This is only the original release of the security bulletin.  It may
not be updated when updates to the original are made.  If downloading at
a later date, it is recommended that the bulletin is retrieved directly
from the author's website to ensure that the information is still current.

Contact information for the authors of the original document is included
in the Security Bulletin above.  If you have any questions or need further
information, please contact them directly.

Previous advisories and external security bulletins can be retrieved from:

        https://www.auscert.org.au/bulletins/

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
===========================================================================
-----BEGIN PGP SIGNATURE-----
Comment: http://www.auscert.org.au/render.html?it=1967

iQIVAwUBXKGje2aOgq3Tt24GAQgdCRAA0U3m8Q8aGq02ypN232tsXitObCXDL/mv
ai3OLuAq9Y0ANGIcEcscCjfVd/+CtuVFKWzVpP5AO8Ownv/601o2iumOwJGoKK3j
Vp85gPJ+QqeDA1x5etdDOapMS0DCwBBPYjN5n/opaAq1vj0hpf48aYZ0CcI7UmH/
f87oRUWm26BVeAzGehVkHdInBm3v+/4NjKTVv+hxcdXOZrcK4wc/HaI35h5Q5+gq
WYa/iADSIpkSpBfA8Uv8/EX5Wa1T6mdwKlG1pVZoCH+qpSVcqhelwdbXtnTJy5g2
sz7rR2AD3OvcsBmT/tbYGfx+Ho2nRzN53rDPpxc2jCcYTLSsDJn4EzdZZKitvy9/
z9Hr6bP0Id6OBOLP+VZTz6XbTTb328dZY7TXJqVRZSMMmRDBRpFWwMWy7CTHj1PN
AipUS6TYqyMDj1uVAI1wTMzAN9eJjp773ISD97UjXJc7vzvB9A7lH0cMYd5Tr0JI
umrU4aPCJ/gXYHe//Ha8w77KANEgCl2rRY6fMHtKV18kNCaQAc3eQrLibgXAxXiR
kWJItdKE3t861r+674tOYpVpSOT+F6WD3/VdUBHpog2TV22IAz0VZhWCgvjKrTz9
tvSy/ghfkft3mTLRf5EpktFqL0vO4Ae6MFbcmLifv3ZiSoGXffy0E86MD2WBKSwx
YPgR1TQkmMs=
=4TGT
-----END PGP SIGNATURE-----

« Back to bulletins