TIBCO LogLogic 5.7.0 Hotfix SEC3-HF-3020 is now available

TIBCO LogLogic 5.7.0 Hotfix SEC3-HF-3020 is now available

book

Article ID: KB0101966

calendar_today

Updated On:

Products Versions
TIBCO LogLogic Log Management Intelligence 5.7.0

Description

This is a cumulative security hotfix to deploy package update for LMI 5.7.0. 
This hotfix includes all previously available cumulative security hotfixes
for TIBCO LogLogic LMI 5.7.0.

This hotfix has no dependencies on any other non-cumulative hotfixes and 
cumulative maintenance hotfixes. It can be used in conjunction with other 
non-cumulative hotfixes and cumulative maintenance hotfixes.

================================================================================
Closed Issues in 5.7.0 SEC3-HF-3020

LLCE-3020:
5.7.0 package updates v3 non-cumulative HF for package updates

The following security issues are resolved with listed packages or newer ones:

bind-utils(ELSA-2018-2571): CVE-2018-5740 by
bind-utils-9.8.2-0.68.rc1.el6_10.1

dhcp(ELSA-2018-1454): CVE-2018-5732, CVE-2018-5733, CVE-2018-1111 by
dhclient-4.1.1-53.P1.0.1.el6_9.4, dhcp-common-4.1.1-53.P1.0.1.el6_9.4

ding-libs (ELSA-2018-1877): CVE-2018-1877 by libcollection-0.6.2-13.el6,
libnl3-3.2.21-8.el6, libini_config-1.1.0-13.el6, libipa_hbac-1.13.3-60.el6,
libpath_utils-0.2.1-13.el6, libref_array-0.1.4-13.el6,
libsss_idmap-1.13.3-60.el6

gnupg2 (ELSA-2018-2180): CVE-2018-12020 by gnupg2-2.0.14-9.el6_10

java-1.8.0-openjdk (ELSA-2018-2241): CVE-2018-3639,CVE-2018-2952, 
CVE-2018-2815, CVE-2018-2814, CVE-2018-2800, CVE-2018-2799, CVE-2018-2798,
CVE-2018-2797, CVE-2018-2796, CVE-2018-2795, CVE-2018-2794, CVE-2018-2790
by java-1.8.0-openjdk-1.8.0.181-3.b13.el6_10,
java-1.8.0-openjdk-headless-1.8.0.181-3.b13.el6_10

nspr (ELEA-2018-1865): nspr-4.19.0-1.el6

nss (ELSA-2018-2898): CVE-2018-12384 by nss-3.36.0-8.el6,
nss-sysinit.3.36.0-8.el6, nss-tools-3.36.0-8.el6, nss-util-3.36.0-1.el6

openssl (ELSA-2018-4248): CVE-2018-0732, CVE-2018-0737, CVE-2018-0739 by
openssl-1.0.1e-57.0.6.el6

procps (ELSA-2018-1777): CVE-2018-1124, CVE-2018-1126 by
procps-3.2.8-45.0.1.el6_9.3

samba (ELSA-2018-1860): CVE-2018-1050 by samba-client-3.6.23-51.0.1.el6,
samba-common-3.6.23-51.0.1.el6, samba-winbind-3.6.23-51.0.1.el6,
samba-winbind-clients-3.6.23-51.0.1.el6

samba4 (ELSA-2018-1883): CVE-2018-1050 by samba4-libs-4.2.10-15.el6

sssd (ELSA-2018-1877): CVE-2017-12173 by sssd-1.13.3-60.el6,
sssd-ad-1.13.3-60.el6, sssd-client-1.13.3-60.el6, sssd-common-1.13.3-60.el6,
sssd-common-pac-1.13.3-60.el6, sssd-ipa-1.13.3-60.el6,
sssd-krb5-1.13.3-60.el6, sssd-krb5-common-1.13.3-60.el6,
sssd-ldap-1.13.3-60.el6, sssd-proxy-1.13.3-60.el6, sssd-tools-1.13.3-60.el6,
python-sss-1.13.3-60.el6, python-sssdconfig-1.13.3-60.el6

yum-utils (ELSA-2018-2284): CVE-2018-10897 by yum-3.2.29-81.el6,
yum-plugin-fastestmirror-1.1.30-41.el6,
yum-plugin-security-1.1.30-42.0.1.el6_10, yum-utils.1.13.30-41.el6

================================================================================
This hotfix can be downloaded from the TIBCO Support Customer Portal at https://support.tibco.com.
You will need to provide your TIBCO Support Portal credentials. Once logged in you can download
the hotfix by selecting “Downloads” -> “Hotfixes” under AvailableDownloads/LogLogic/LMI/6.1.1_Hotfixes

Environment

All TIBCO LogLogic LMI and EVA appliances running software version 5.7.0

Resolution

Install this security hotfix following the instructions in the attached Readme

Issue/Introduction

TIBCO LogLogic 5.7.0 Hotfix SEC3-HF-3020 is now available

Attachments

TIBCO LogLogic 5.7.0 Hotfix SEC3-HF-3020 is now available get_app