Dell patches virtual storage software against OpenSSL, Apache bugs

By
Follow google news

Text4Shell among the bug-fixes.

Dell has been moved to patch vulnerabilities inherited from Apache and OpenSSL.

Dell patches virtual storage software against OpenSSL, Apache bugs

The fixes are for the Dell Virtual Storage Integrator for VMware vSphere client and are outlined in this advisory.

The Apache fix is for the Text4Shell vulnerability, CVE-2022-42889, revealed in mid-October. 

In some cases, the CVE advisory explained, Apache Commons versions 1.5 to 1.9 use a Java text manipulation library that can be attacked to gain access to the underlying host.

The OpenSSL bugs, CVE-2022-3602 and CVE-2022-3786, are buffer overruns in how the encryption library handles X.509 certificates and were disclosed and patched earlier this month.

Dell has also updated two older advisories covering its EMC VxRail software.

In one, fixes have been added for a number of VxM SUSE Linux bugs; and in the other, a number of CVEs have been added to the advisory.

Add iTnews as your trusted source

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:

Most Read Articles

NAB's CSO to move to ANZ Banking Group

NAB's CSO to move to ANZ Banking Group

Services Australia describes fraud, debt-related machine learning use cases

Services Australia describes fraud, debt-related machine learning use cases

Privacy Act overhaul to tighten 72-hour breach reporting deadline

Privacy Act overhaul to tighten 72-hour breach reporting deadline

Two Aussies alleged to be "principal participants" of TeamPCP hacking group

Two Aussies alleged to be "principal participants" of TeamPCP hacking group

Log In

  |  Forgot your password?