BugTraq
[security bulletin] HPSBST03642 rev.3 - HPE StoreVirtual Products running LeftHand OS using OpenSSL and OpenSSH, Remote Arbitrary Code Execution, Denial of Service (DoS), Disclosure of Sensitive Information, Unauthorized Access Jan 24 2017 10:01PM
security-alert hpe com
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Note: the current version of the following document is available here:

https://h20564.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-c053019
46

SUPPORT COMMUNICATION - SECURITY BULLETIN

Document ID: c05301946

Version: 3

HPSBST03642 rev.3 - HPE StoreVirtual Products running LeftHand OS using

OpenSSL and OpenSSH, Remote Arbitrary Code Execution, Denial of Service

(DoS), Disclosure of Sensitive Information, Unauthorized Access

NOTICE: The information in this Security Bulletin should be acted upon as

soon as possible.

Release Date: 2017-01-24

Last Updated: 2017-01-24

Potential Security Impact: Remote: Arbitrary Code Execution, Denial of

Service (DoS), Disclosure of Sensitive Information, Unauthorized Access

Source: Hewlett Packard Enterprise, Product Security Response Team

VULNERABILITY SUMMARY

Security vulnerabilities in OpenSSL and OpenSSH were addressed in HPE

StoreVirtual products using LeftHand OS. These vulnerabilities include:

* The SSLv3 vulnerability known as "Padding Oracle on Downgraded Legacy

Encryption" also known as "POODLE", which could be exploited remotely

resulting in disclosure of information.

* Additional OpenSSL and OpenSSH vulnerabilities which could be remotely

exploited resulting in arbitrary code execution, unauthorized access,

disclosure of information, or Denial of Service (DoS).

References:

- CVE-2016-0705 - Double-free in DSA private key parsing

- CVE-2014-0224 - SSL/TLS man-in-the-middle (MITM) vulnerability

- CVE-2014-0221 - Denial of Service (DoS)

- CVE-2014-0195 - Buffer overflow via DTLS invalid fragment

- CVE-2014-0198 - SSL_MODE_RELEASE_BUFFERS NULL pointer dereference

- CVE-2014-3470 - Client-side denial of service when using anonymous ECDH

- CVE-2014-0076 - ECDSA nonces susceptible to Yarom/Benger flush+reload

cache side-channel attack

- CVE-2014-3566 - POODLE - SSLv3 vulnerability

- CVE-2010-5298 - SSL_MODE_RELEASE_BUFFERS session injection or denial of

service

SUPPORTED SOFTWARE VERSIONS*: ONLY impacted versions are listed.

- HP StoreVirtual VSA Software 12.6, 12.5, 12.0, 11.5

- HP StoreVirtual 4130 600GB SAS Storage 12.6, 12.5, 12.0, 11.5

- HP StoreVirtual 4130 600GB China SAS Storage 12.6, 12.5, 12.0, 11.5

- HP StoreVirtual 4330 1TB MDL SAS Storage 12.6, 12.5, 12.0, 11.5

- HP StoreVirtual 4330 450GB SAS Storage 12.6, 12.5, 12.0, 11.5

- HP StoreVirtual 4330 900GB SAS Storage 12.6, 12.5, 12.0, 11.5

- HP StoreVirtual 4330 1TB MDL China SAS Storage 12.6, 12.5, 12.0, 11.5

- HP StoreVirtual 4330 450GB China SAS Storage 12.6, 12.5, 12.0, 11.5

- HP StoreVirtual 4330 900GB China SAS Storage 12.6, 12.5, 12.0, 11.5

- HP StoreVirtual 4330 FC 900GB SAS Storage 12.6, 12.5, 12.0, 11.5

- HP StoreVirtual 4330 FC 900GB China SAS Storage 12.6, 12.5, 12.0, 11.5

- HP StoreVirtual 4530 2TB MDL SAS Storage 12.6, 12.5, 12.0, 11.5

- HP StoreVirtual 4530 3TB MDL SAS Storage 12.6, 12.5, 12.0, 11.5

- HP StoreVirtual 4530 450GB SAS Storage 12.6, 12.5, 12.0, 11.5

- HP StoreVirtual 4530 600GB SAS Storage 12.6, 12.5, 12.0, 11.5

- HP StoreVirtual 4630 900GB SAS Storage 12.6, 12.5, 12.0, 11.5

- HP StoreVirtual 4730 600GB SAS Storage 12.6, 12.5, 12.0, 11.5

- HP StoreVirtual 4730 900GB SAS Storage 12.6, 12.5, 12.0, 11.5

- HP StoreVirtual 4730 FC 900GB SAS Storage 12.6, 12.5, 12.0, 11.5

- HP StoreVirtual 4330 450GB SAS Storage/S-Buy 12.6, 12.5, 12.0, 11.5

- HP StoreVirtual 4330 900GB SAS Storage/S-Buy 12.6, 12.5, 12.0, 11.5

- HP StoreVirtual 4330 1TB MDL SAS Storage/S-Buy 12.6, 12.5, 12.0, 11.5

- HP StoreVirtual 4530 3TB MDL SAS Storage/S-Buy 12.6, 12.5, 12.0, 11.5

- HP StoreVirtual 4530 450GB SAS Storage/S-Buy 12.6, 12.5, 12.0, 11.5

- HP StoreVirtual 4335 China Hybrid Storage 12.6, 12.5, 12.0, 11.5

- HP StoreVirtual 4335 Hybrid Storage 12.6, 12.5, 12.0, 11.5

- HP StoreVirtual 4530 4TB MDL SAS Storage 12.6, 12.5, 12.0, 11.5

- HP StoreVirtual 4130 600GB China SAS Storage 12.6, 12.5, 12.0, 11.5

- HP StoreVirtual 4130 600GB SAS Storage 12.6, 12.5, 12.0, 11.5

- HP StoreVirtual 4330 1TB MDL China SAS Storage 12.6, 12.5, 12.0, 11.5

- HP StoreVirtual 4330 1TB MDL SAS Storage 12.6, 12.5, 12.0, 11.5

- HP StoreVirtual 4330 1TB MDL SAS Storage/S-Buy 12.6, 12.5, 12.0, 11.5

- HP StoreVirtual 4330 450GB China SAS Storage 12.6, 12.5, 12.0, 11.5

- HP StoreVirtual 4330 450GB SAS Storage 12.6, 12.5, 12.0, 11.5

- HP StoreVirtual 4330 450GB SAS Storage/S-Buy 12.6, 12.5, 12.0, 11.5

- HP StoreVirtual 4330 900GB China SAS Storage 12.6, 12.5, 12.0, 11.5

- HP StoreVirtual 4330 900GB SAS Storage 12.6, 12.5, 12.0, 11.5

- HP StoreVirtual 4330 900GB SAS Storage/S-Buy 12.6, 12.5, 12.0, 11.5

- HP StoreVirtual 4330 FC 900GB China SAS Storage 12.6, 12.5, 12.0, 11.5

- HP StoreVirtual 4330 FC 900GB SAS Storage 12.6, 12.5, 12.0, 11.5

- HP StoreVirtual 4335 China Hybrid SAN Solution 12.6, 12.5, 12.0, 11.5

- HP StoreVirtual 4335 China Hybrid Storage 12.6, 12.5, 12.0, 11.5

- HP StoreVirtual 4335 Hybrid SAN Solution 12.6, 12.5, 12.0, 11.5

- HP StoreVirtual 4335 Hybrid Storage 12.6, 12.5, 12.0, 11.5

- HP StoreVirtual 4530 2TB MDL SAS Storage 12.6, 12.5, 12.0, 11.5

- HP StoreVirtual 4530 3TB MDL SAS Storage 12.6, 12.5, 12.0, 11.5

- HP StoreVirtual 4530 3TB MDL SAS Storage/S-Buy 12.6, 12.5, 12.0, 11.5

- HP StoreVirtual 4530 450GB SAS Storage 12.6, 12.5, 12.0, 11.5

- HP StoreVirtual 4530 450GB SAS Storage/S-Buy 12.6, 12.5, 12.0, 11.5

- HP StoreVirtual 4530 4TB MDL SAS Storage 12.6, 12.5, 12.0, 11.5

- HP StoreVirtual 4530 600GB SAS Storage 12.6, 12.5, 12.0, 11.5

- HP StoreVirtual 4530 600GB SAS Storage/S-Buy 12.6, 12.5, 12.0, 11.5

- HP StoreVirtual 4630 900GB SAS Storage 12.6, 12.5, 12.0, 11.5

- HP StoreVirtual 4730 600GB SAS Storage 12.6, 12.5, 12.0, 11.5

- HP StoreVirtual 4730 600GB SAS Storage/S-Buy 12.6, 12.5, 12.0, 11.5

- HP StoreVirtual 4730 900GB SAS Storage 12.6, 12.5, 12.0, 11.5

- HP StoreVirtual 4730 900GB SAS Storage/S-Buy 12.6, 12.5, 12.0, 11.5

- HP StoreVirtual 4730 FC 900GB SAS Storage 12.6, 12.5, 12.0, 11.5

BACKGROUND

CVSS Base Metrics

=================

Reference, CVSS V3 Score/Vector, CVSS V2 Score/Vector

CVE-2010-5298

4.8 CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L

4.0 (AV:N/AC:H/Au:N/C:N/I:P/A:P)

CVE-2014-0076

4.0 CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

1.9 (AV:L/AC:M/Au:N/C:P/I:N/A:N)

CVE-2014-0195

7.3 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

6.8 (AV:N/AC:M/Au:N/C:P/I:P/A:P)

CVE-2014-0198

5.3 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

4.3 (AV:N/AC:M/Au:N/C:N/I:N/A:P)

CVE-2014-0221

5.3 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

4.3 (AV:N/AC:M/Au:N/C:N/I:N/A:P)

CVE-2014-0224

6.5 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

6.8 (AV:N/AC:M/Au:N/C:P/I:P/A:P)

CVE-2014-3470

5.3 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

4.3 (AV:N/AC:M/Au:N/C:N/I:N/A:P)

CVE-2014-3566

3.1 CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N

4.3 (AV:N/AC:M/Au:N/C:P/I:N/A:N)

CVE-2016-0705

9.8 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

10.0 (AV:N/AC:L/Au:N/C:C/I:C/A:C)

Information on CVSS is documented in

HPE Customer Notice HPSN-2008-002 here:

https://h20564.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-c013454
99

RESOLUTION

HPE recommends applying the following software updates to resolve the

vulnerabilities in the impacted versions of HPE StoreVirtual products running

HPE LeftHand OS.

LeftHand OS v11.5 - Patches 45019-00 and 45020

LeftHand OS v12.0 - Patches 50016-00 and 50017-00

LeftHand OS v12.5 - Patch 55016-00

LeftHand OS v12.6 - Patch 56002-00

**Notes:**

These patches enable TLSv1.2 protocol and upgrades the OpenSSL RPM revision

to OpenSSL v1.0.1e 48.

These patches migrate Certificate Authority Hashing Algorithm from a weak

hashing algorithm SHA1 to the stronger hashing algorithm SHA256.

HISTORY

Version:1 (rev.1) - 7 October 2016 Initial release

Version:2 (rev.2) - 13 October 2016 Updated the Resolution section

Version:3 (rev.3) - 24 January 2017 Added patch information in the Resolution

section

Third Party Security Patches: Third party security patches that are to be

installed on systems running Hewlett Packard Enterprise (HPE) software

products should be applied in accordance with the customer's patch management

policy.

Support: For issues about implementing the recommendations of this Security

Bulletin, contact normal HPE Services support channel. For other issues about

the content of this Security Bulletin, send e-mail to security-alert (at) hpe (dot) com. [email concealed]

Report: To report a potential security vulnerability for any HPE supported

product:

Web form: https://www.hpe.com/info/report-security-vulnerability

Email: security-alert (at) hpe (dot) com [email concealed]

Subscribe: To initiate a subscription to receive future HPE Security Bulletin

alerts via Email: http://www.hpe.com/support/Subscriber_Choice

Security Bulletin Archive: A list of recently released Security Bulletins is

available here: http://www.hpe.com/support/Security_Bulletin_Archive

Software Product Category: The Software Product Category is represented in

the title by the two characters following HPSB.

3C = 3COM

3P = 3rd Party Software

GN = HPE General Software

HF = HPE Hardware and Firmware

MU = Multi-Platform Software

NS = NonStop Servers

OV = OpenVMS

PV = ProCurve

ST = Storage Software

UX = HP-UX

Copyright 2016 Hewlett Packard Enterprise

Hewlett Packard Enterprise shall not be liable for technical or editorial

errors or omissions contained herein. The information provided is provided

"as is" without warranty of any kind. To the extent permitted by law, neither

HP or its affiliates, subcontractors or suppliers will be liable for

incidental,special or consequential damages including downtime cost; lost

profits; damages relating to the procurement of substitute products or

services; or damages for loss of data, or software restoration. The

information in this document is subject to change without notice. Hewlett

Packard Enterprise and the names of Hewlett Packard Enterprise products

referenced herein are trademarks of Hewlett Packard Enterprise in the United

States and other countries. Other product and company names mentioned herein

may be trademarks of their respective owners.

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQEcBAEBCAAGBQJYh5ZbAAoJELXhAxt7SZai5e4H/2tDfMtCrWbXoH0tYtJqBWKp
ho1RVv4dbtFCk4bi7q13saVBzpsPJXRbnSUMVkkytQDtQRxrzQvDbdp6bMVUuLk8
wlslW2wSC5Aj+fvIoTMu/7cizQh8FS2aO44l/+bFujyUFiUSR68BEzCgMsI9f2vy
RH95/frYNpLw16Jw5/OljT1xvMWIrcTnrjKVe1Jpcp5jgbuIlR1RPi4JITKz+vHY
tSyf2V2UlsPGTYEnt2b6RdRdVs3legawVcbNpA25FJQP3PRZiOrJvxHbzrZcPATT
id22oU9U3cEvG2oQe2gI3wNWQBF1vU/t7vXJ9VImO7qPmhpFDWdKUzhKULlEGQI=
=gw/2
-----END PGP SIGNATURE-----

[ reply ]


 

Privacy Statement
Copyright 2010, SecurityFocus