TIBCO LogLogic 6.2.1 Hotfix SEC2-HF-3272 is now available

TIBCO LogLogic 6.2.1 Hotfix SEC2-HF-3272 is now available

book

Article ID: KB0101493

calendar_today

Updated On:

Products Versions
TIBCO LogLogic Log Management Intelligence 6.2.1

Description

This is a cumulative security hotfix to deploy package update for LMI 6.2.1. 
This hotfix includes all previously available cumulative security hotfixes
for TIBCO LogLogic LMI 6.2.1.

This hotfix has no dependencies on any other non-cumulative hotfixes and 
cumulative maintenance hotfixes. It can be used in conjunction with other 
non-cumulative hotfixes and cumulative maintenance hotfixes.
================================================================================
Closed Issues in 6.2.1 SEC2-HF-3272

LLCE-3272:
6.2.1 package updates v2 cumulative HF for package updates

LLCE-3330:
openssh : OEL Security Update for openssh (ELSA-2019-0711)

LLCE-3329:
polkit : OEL Security Update for polkit (ELSA-2019-0420)

LLCE-3328:
openjdk : OEL Security Update for java-1.8.0-openjdk 

LLCE-3327:
OEL Security Update for sssd and ding-libs

LLCE-3325:
ntp : OEL Security Update for ntp (ELSA-2018-3854)



The following security issues are resolved with listed packages or newer ones:

bind (ELSA-2019-1492):CVE-2018-5743 by bind-libs-9.8.2-0.68.rc1.el6_10.3.x86_64,
bind-utils-9.8.2-0.68.rc1.el6_10.3.x86_64

dhcp (ELBA-2018-2900): dhclient-4.1.1-63.P1.0.1.el6_10.x86_64,
dhcp-common-4.1.1-63.P1.0.1.el6_10.x86_64

ding-libs (ELBA-2018-4209) : libipa_hbac-1.13.3-60.0.2.el6.x86_64,
libsss_idmap-1.13.3-60.0.2.el6.x86_64

gnupg2 (ELSA-2018-2180): CVE-2018-12020 gnupg2-2.0.14-9.el6_10.x86_64

java-1.8.0-openjdk (ELSA-2019-0774) : CVE-2019-2602,CVE-2019-2684,CVE-2019-2698 by
java-1.8.0-openjdk-1.8.0.212.b04-0.el6_10.x86_64,
java-1.8.0-openjdk-devel-1.8.0.212.b04-0.el6_10.x86_64,
java-1.8.0-openjdk-headless-1.8.0.212.b04-0.el6_10.x86_64

ntp (ELSA-2018-3854) : CVE-2018-12327 by ntp-4.2.6p5-15.0.1.el6_10.x86_64,
ntpdate-4.2.6p5-15.0.1.el6_10.x86_64

nspr (ELEA-2019-3280): nspr-4.21.0-1.el6_10.i686, nspr-4.21.0-1.el6_10.x86_64

nss (ELSA-2018-2898):CVE-2018-12384 by nss-3.36.0-9.0.1.el6_10.x86_64,
nss-sysinit-3.36.0-9.0.1.el6_10.x86_64, nss-tools-3.36.0-9.0.1.el6_10.x86_64,
nss-util-3.36.0-1.el6.i686,nss-util-3.36.0-1.el6.x86_64

openssh (ELSA-2019-0711): CVE-2018-15473 by openssh-5.3p1-124.el6_10.x86_64,
openssh-clients-5.3p1-124.el6_10.x86_64,
openssh-server-5.3p1-124.el6_10.x86_64

polkit (ELSA-2019-0420):CVE-2019-6133 by
polkit-0.96-11.el6_10.1.x86_64

procps (ELSA-2018-1777):CVE-2018-1124,CVE-2018-1126 by
procps-3.2.8-45.0.1.el6_9.3.x86_64

samba4 (ELSA-2018-1883): CVE-2018-1050 by ssamba4-client-4.2.10-15.el6.x86_64,
samba4-common-4.2.10-15.el6.x86_64, samba4-libs-4.2.10-15.el6.x86_64

sssd (ELSA-2018-1877),(ELBA-2018-4209) : CVE-2017-12173 by 
python-sss-1.13.3-60.0.2.el6_10.2.x86_64,
python-sssdconfig-1.13.3-60.0.2.el6_10.2.noarch, 
sssd-1.13.3-60.0.2.el6_10.2.x86_64, 
sssd-ad-1.13.3-60.0.2.el6_10.2.x86_64, 
sssd-client-1.13.3-60.0.2.el6.x86_64,
sssd-common-1.13.3-60.0.2.el6.x86_64, 
sssd-common-pac-1.13.3-60.0.2.el6.x86_64,
sssd-ipa-1.13.3-60.0.2.el6.x86_64, 
sssd-krb5-1.13.3-60.0.2.el6.x86_64,
sssd-krb5-common-1.13.3-60.0.2.el6.x86_64, 
sssd-ldap-1.13.3-60.0.2.el6.x86_64,
sssd-proxy-1.13.3-60.0.2.el6.x86_64, 
sssd-tools-1.13.3-60.0.2.el6.x86_64,
libbasicobjects-0.1.1-13.el6.x86_64,
libcollection-0.6.2-13.el6.x86_64,
libdhash-0.4.3-13.el6.x86_64,
libini_config-1.1.0-13.el6.x86_64,
libipa_hbac-1.13.3-60.0.2.el6_10.2.x86_64,
libpath_utils-0.2.1-13.el6.x86_64,
libref_array-0.1.4-13.el6.x86_64,
libsss_idmap-1.13.3-60.0.2.el6_10.2.x86_64

yum-utils ( ELSA-2018-2284) :CVE-2018-10897 by yum-3.2.29-81.0.1.el6.noarch.rpm,
yum-plugin-fastestmirror-1.1.30-42.0.1.el6_10.noarch.rpm,
yum-plugin-security-1.1.30-42.0.1.el6_10.noarch.rpm, 
yum-utils-1.1.30-42.0.1.el6_10.noarch.rpm
================================================================================
This hotfix can be downloaded from the TIBCO Support Customer Portal at https://support.tibco.com.
You will need to provide your TIBCO Support Portal credentials. Once logged in you can download
the hotfix by selecting “Downloads” -> “Hotfixes” under AvailableDownloads/LogLogic/LMI/6.2.1_Hotfixes

Environment

All TIBCO LogLogic LMI and EVA appliances running software version 6.2.1

Resolution

Install this security hotfix following the instructions in the attached Readme

Issue/Introduction

TIBCO LogLogic 6.2.1 Hotfix SEC2-HF-3272 is now available

Attachments

TIBCO LogLogic 6.2.1 Hotfix SEC2-HF-3272 is now available get_app