-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

===========================================================================
             AUSCERT External Security Bulletin Redistribution

                               ESB-2016.0492
    Action required for IBM Integration Bus Hypervisor Edition V9.0 and
           WebSphere Message Broker Hypervisor Edition V8.0 for
            security vulnerabilities in Red Hat (CVE-2015-7547)
                             25 February 2016

===========================================================================

        AusCERT Security Bulletin Summary
        ---------------------------------

Product:           IBM Integration Bus Hypervisor Edition
Publisher:         IBM
Operating System:  Linux variants
Impact/Access:     Access Privileged Data -- Remote with User Interaction
                   Denial of Service      -- Remote with User Interaction
Resolution:        Patch/Upgrade
CVE Names:         CVE-2015-7547  

Original Bulletin: 
   http://www.ibm.com/support/docview.wss?uid=swg21977378

- --------------------------BEGIN INCLUDED TEXT--------------------

Action required for IBM Integration Bus Hypervisor Edition V9.0 and WebSphere
Message Broker Hypervisor Edition V8.0 for security vulnerabilities in
Red Hat (CVE-2015-7547)

Document information

More support for:
IBM Integration Bus Hypervisor Edition

Software version:
9.0

Operating system(s):
Linux

Reference #:
1977378

Modified date:
2016-02-24


Flash (Alert)

Abstract

IBM Integration Bus Hypervisor Edition V9.0 and WebSphere Message Broker
Hypervisor Edition V8.0 require customer action for security vulnerabilities
in Red Hat (CVE-2015-7547)

Content

IBM Integration Bus Hypervisor Edition V9.0 and WebSphere Message Broker
Hypervisor Edition V8.0 ship with versions of Red Hat Enterprise Linux
(RHEL) Server that are vulnerable to GNU C Library (glibc) - stack-based
buffer overflow (CVE-2015-7547)

IBM Integration Bus Hypervisor Edition V9.0 and WebSphere Message Broker
Hypervisor Edition V8.0 ship with Red Hat Enterprise Linux (RHEL) Server 6.2.

Remediation:

IBM strongly recommends that you contact Red Hat provider to obtain and
install fixes for Red Hat Enterprise Linux (RHEL) Server 6.2 as applicable
Related information

google

Cross reference information 

Segment	Product		Component					Platform	Version		Edition
Business Integration	WebSphere Message Broker Hypervisor Edition	Linux		8.0

Product Alias/Synonym

WebSphere Message Broker WMB IBM Integration Bus IIB

- --------------------------END INCLUDED TEXT--------------------

You have received this e-mail bulletin as a result of your organisation's
registration with AusCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.

NOTE: Third Party Rights
This security bulletin is provided as a service to AusCERT's members.  As
AusCERT did not write the document quoted above, AusCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AusCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.

NOTE: This is only the original release of the security bulletin.  It may
not be updated when updates to the original are made.  If downloading at
a later date, it is recommended that the bulletin is retrieved directly
from the author's website to ensure that the information is still current.

Contact information for the authors of the original document is included
in the Security Bulletin above.  If you have any questions or need further
information, please contact them directly.

Previous advisories and external security bulletins can be retrieved from:

        http://www.auscert.org.au/render.html?cid=1980

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
===========================================================================
-----BEGIN PGP SIGNATURE-----
Comment: http://www.auscert.org.au/render.html?it=1967

iQIVAwUBVs6C6X6ZAP0PgtI9AQLfYBAAwLKT6GWnZCRvHFa3EK8Dxo+tibS2tr5y
wLJtEY+Do1NoVkDvweX0336A8A9ppdtuJt1GWChN0Xibs9XjuD6fx3rOgpskGlmS
JsbUdJWXbJhB+HjI76yDtBachwaOzzueyLi9g7KYYQCrDdP5AbEzxwDlYbo92j4G
WjqL+gSvbbDZkP6mMIL/XS1XKoRvSpYdi44UTYMgPpQieyRSWHG34/ngFIdnyMZt
iiUYtksHuf1SUz8XItAO9uuQCoNmKNwr4QlLMws6NG7J8CWOnCcEf9VPkSioq9DW
y8yiz+c/+jthPstnQrbZ3VHnRImw0PXpPdrXJcN5vMdm4TR4XdD7rrJmnNqGtv0L
3+tBJ94BbkWTimmxeU82n+7m2diIv5bdB5Daw3uQq5R6PR4gJg00jrMl4tE8yjLU
FQIslwy88TWD+QmqhDSbgjzHgvYOcy3De2RXnnXCOOl72Sa0fXrG1S9ptWeTcyAa
EGLTShgbjCOF/WV6wJpnP+4hWS3VUXkppKO4tQFK8nlm0P7DFajMOnIakwaOZKG+
2xBpFS5LSDw6/JG65SVEn9sojI16yeb7TCxZvKtpg1fqlhh3MYdW23aQjRG36yiM
MrBI9EtnALNs6j1QlPReylTkfF4pJVQgS+w0qW4M0LtIL1Yap4DxyYG95zK+neS6
6fBrbPfBuno=
=mpeF
-----END PGP SIGNATURE-----