PT-2018-12372 · Ibm · Ibm Db2+2

Publicado

2018-03-22

·

Atualizado

2020-08-24

·

CVE-2018-1426

CVSS v3.1

9.1

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions IBM GSKit (IBM DB2 for Linux, UNIX and Windows) versions 9.7 through 11.1
Description The issue concerns a problem with the PRNG state being duplicated across fork() system calls when multiple ICC instances are loaded, potentially leading to duplicate Session IDs and a risk of duplicate key material. Additionally, the GSKit CMS KDB logic fails to properly salt the hash function, resulting in weaker protection of passwords, which may allow a weak password to be recovered.
Recommendations For versions 9.7 through 11.1, update the software to address the issue with PRNG state duplication and hash function salting, and then change passwords to ensure they are stored more securely.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-1426

Produtos afetados

Ibm Aix
Ibm Db2
Ibm Gskit