[ GLSA 202209-02 ] IBM Spectrum Protect: Multiple Vulnerabilities

[email protected]
Newsgroups gmane.linux.gentoo.announce
Message-ID <166251913483.14.1322884666903921553@713d1c2c1be1>
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory                           GLSA 202209-02
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
                                           https://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

 Severity: High
    Title: IBM Spectrum Protect: Multiple Vulnerabilities
     Date: September 07, 2022
     Bugs: #788115, #829189, #831509
       ID: 202209-02

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
========

Multiple vulnerabilities have been discovered in IBM Spectrum Protect,
the worst of which could result in arbitrary code execution.

Background
==========

TSM provides the client and the API for IBM Spectrum Protect (formerly
known as Tivoli Storage Manager), a backup and archival client/server
solution targetting large tape libraries.

Affected packages
=================

    -------------------------------------------------------------------
     Package              /     Vulnerable     /            Unaffected
    -------------------------------------------------------------------
  1  app-backup/tsm             < 8.1.13.3                >= 8.1.13.3

Description
===========

Multiple vulnerabilities have been discovered in IBM Spectrum Protect.
Please review the CVE identifiers referenced below for details.

Impact
======

Please review the referenced CVE identifiers for details.

Workaround
==========

There is no known workaround at this time.

Resolution
==========

All IBM Spectrum Protect users should upgrade to the latest version:

  # emerge --sync
  # emerge --ask --oneshot --verbose ">=app-backup/tsm-8.1.13.3"

References
==========

[ 1 ] CVE-2021-3711
      https://nvd.nist.gov/vuln/detail/CVE-2021-3711
[ 2 ] CVE-2021-3712
      https://nvd.nist.gov/vuln/detail/CVE-2021-3712
[ 3 ] CVE-2021-4104
      https://nvd.nist.gov/vuln/detail/CVE-2021-4104
[ 4 ] CVE-2021-29672
      https://nvd.nist.gov/vuln/detail/CVE-2021-29672
[ 5 ] CVE-2021-39048
      https://nvd.nist.gov/vuln/detail/CVE-2021-39048

Availability
============

This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:

 https://security.gentoo.org/glsa/202209-02

Concerns?
=========

Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users' machines is of utmost
importance to us. Any security concerns should be addressed to
[email protected] or alternatively, you may file a bug at
https://bugs.gentoo.org.

License
=======

Copyright 2022 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).

The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.

https://creativecommons.org/licenses/by-sa/2.5
signature.asc (application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEpqTA6ABLMxh/aChGFMQkOaVy+9kFAmMYB14ACgkQFMQkOaVy
+9nXSA//dRNBtqNRx7Bp9kXem99O6ISVBkDOKF8DFRjb1wy3/v3/I0Cv3qRQ1aHJ
uUjfaZsmnXwiVfXekucdSbvY2cExtGw8+fSmwNbcRmaFnIa5ZPBoPLcCoAp78Nn9
TQe1hTJLlVhzExCCH7xHiIbKMmuZd24b3qH0MIIrUFmbNliopczE9hWc6yk+df/c
hprV9Dp+lGKDNXf0MWBvIDvnu/ATnFDRQqnGrxnC1IcOThjTZyOhb+Vt05ok5u1s
tdN4vGOmOUNWNID+o1QkcCeCfsgFetCK9R0e/Bsk1JFk6gGGe1OFIz/WSltTjyMG
Ug+efY2b4BBr7qwcrwCJBELF4WPsH+IDy57nuzk9K5eoNjLsy7V+GEDcSHe1zIcu
AFepSEPQKizAPj+sl2HVHH8A10KGFqhCkypdcYVa2EBulgx+ERuOgwmwfKY3n18U
fgCnFcy1YI7O6FVliVcbN8SiBeRMvReSwSXuokNNrNaj1+0LlPemFgV4NJj8gH8e
GYBmnvMd43nzWy8uVJjaYPWSwvi4xuJ5pVQJZ/FBEl7btgkZISJBEueVMK18ClsU
uxrMDwsshy/jNKirrfLqgjLnXsoLYOkwmAI3mGg9wUWihXT3HliNi9yXXX9Vf3+F
IeR+Wy2/lkeP53QMZJmbJczde/3cg8k8nHkmdvbRXZlUKnfwmF8=
=o2YR
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.