Brocade Security Advisory ID: BSA-2016-006
Initial Publication Date: May 11, 2016
Revision: 3.0
Revision Date: April 7, 2017
Page 7
Component: OpenSSL
CVSS Score: 4.3
CVE-2015-3196: https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-3196
ssl/s3_clnt.c in OpenSSL 1.0.0 before 1.0.0t, 1.0.1 before 1.0.1p, and 1.0.2 before 1.0.2d, when used
for a multi-threaded client, writes the PSK identity hint to an incorrect data structure, which allows remote
servers to cause a denial of service (race condition and double free) via a crafted ServerKeyExchange
message.
Impacted - Fixed in 6.7R10.
Impacted - Fixed in 3.5R7.
Impacted – Fixed in 8.0.1/7.4.1d.
Brocade ServerIron JetCore
Brocade Virtual Traffic Manager
(formerly Brocade SteelApp Traffic
Manager (STM))
Impacted - Upgrade appliances to version 10.3 and later.
Fixed in 9.9r1 for customers using the 9.9 LTS release.
Brocade vTM software customers are not affected.
Brocade Services Director (formerly
SteelApp Services Controller (SSC))
Impacted - Brocade Services Director VA customers
should upgrade to use at least version 2.2 of the Services
Director VA, or to version 2.4 (or later) of the Services
Director VA and Instance Host VA if the Instance Host is in
use.
Brocade Virtual Web Application
Firewall (formerly Brocade SteelApp
Application Firewall (SAF))
Impacted - Update to 4.9-37890, 2.1-37890, and later.
Impacted - Upgrade to 14.0.
Brocade IronView Network
Manager
Brocade Data Center Fabric
Manager