QID 330131

Date Published: 2023-03-08

QID 330131: IBM AIX Denial of Service (DoS) due to zlib and zlibNX (zlib_advisory)

AIX is vulnerable to a denial of service due to zlib and zlibNX

For zlib, rpm.rte impacted for 7.1,7.2,7.3 For zlibNX zlibNX.rte impacted for 7.2 and 7.3 Affected Platform:
AIX 7.1,7.2, 7.3
QID Detection Logic (Authenticated):
The detection checks for installed packages version via command : lslpp -L | grep -i rpm.rte and zlibNX.rte It also checks for interim fixes for zlibNX.rte installed using the command emgr -c; or instfix -k. The detection posts vulnerable if installed package version is less than patched version and interim fixes are also not installed.

Successful exploitation may lead to denial of service

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    The vendor has released fixes to zlib_advisory this vulnerability.

    CVEs related to QID 330131

    Software Advisories
    Advisory ID Software Component Link
    zlib_advisory URL Logo aix.software.ibm.com/aix/efixes/security/zlib_advisory.asc