{"status":"success","advisory":{"_id":"6835471f5b16347a91c39c52","kb_acknowledgements":null,"kb_affected_list":["FlashRay","NetApp VASA Provider for Clustered Data ONTAP 6.x","NetApp VTL","OnCommand Balance","RapidData Migration Solution","SnapDrive for Unix","SnapProtect","StorageGRID (formerly StorageGRID Webscale)","StorageGRID9 (9.x and prior)"],"kb_bad_data":false,"kb_cve":["CVE-2015-0235"],"kb_exploitation":"Public","kb_fixes":[{"product":"SnapProtect","fixes":[],"instructions":"SnapProtect may directly or indirectly invoke the affected functions but does not bundle the library - the host OS library must be updated for the fix. \r\nhttp://docs.commvault.com/commvault/v10/article?p=announcement/announcements.htm","wontfix":false,"eos_link":null},{"product":"NetApp VASA Provider for Clustered Data ONTAP 6.x","fixes":[{"link":"http://mysupport.netapp.com/NOW/download/software/vasa_cdot/6.2/","cves":[]}],"instructions":"","wontfix":false,"eos_link":null},{"product":"OnCommand Balance","fixes":[{"link":"http://mysupport.netapp.com/NOW/download/software/oncommand_ib/4.2P4/","cves":[]}],"instructions":"","wontfix":false,"eos_link":null},{"product":"FlashRay","fixes":[],"instructions":null,"wontfix":true,"eos_link":"n/a"},{"product":"RapidData Migration Solution","fixes":[],"instructions":null,"wontfix":true,"eos_link":null},{"product":"StorageGRID (formerly StorageGRID Webscale)","fixes":[{"link":"http://mysupport.netapp.com/NOW/download/software/storagegrid_webscale/10.3.0/","cves":[]}],"instructions":"Apply Novell SLES Security Patches https://kb.netapp.com/support/index?page=content&id=1014874","wontfix":false,"eos_link":null},{"product":"SnapDrive for Unix","fixes":[],"instructions":"SnapDrive for Unix uses the affected gethostbyname() function but does not bundle the library - the host OS library must be updated for the fix.\r\n","wontfix":false,"eos_link":null},{"product":"NetApp VTL","fixes":[],"instructions":null,"wontfix":true,"eos_link":"mysupport.netapp.com/info/eoa/df_eoa_category_page.html?category=Platforms#ECMLP2562710"},{"product":"StorageGRID9 (9.x and prior)","fixes":[],"instructions":"Apply Novell SLES Security Patches https://kb.netapp.com/support/index?page=content&id=1014874","wontfix":false,"eos_link":null}],"kb_impact":"Exploitation of this vulnerability may lead to arbitrary code execution.","kb_internal_notes":[{"burt":"885147","jira":"","product":"Brocade Fabric Operating System Firmware"},{"burt":"885149","jira":"","product":"Brocade Fabric Operating System Firmware"},{"burt":"885148","jira":"","product":"Brocade Network Advisor Software"},{"burt":"885158","jira":"","product":"Cluster Network Switch (NetApp CN1610)"},{"burt":"883982","jira":"","product":"Clustered Data ONTAP"},{"burt":"883983","jira":"","product":"Clustered Data ONTAP"},{"burt":"883988","jira":"","product":"Data ONTAP Edge"},{"burt":"883978","jira":"","product":"FlashRay"},{"burt":"883986","jira":"","product":"NetApp NFS Plug-in for VMware VAAI"},{"burt":"","jira":"","product":"NetApp SolidFire, Enterprise SDS & HCI Storage Node (Element Software)"},{"burt":"883987","jira":"","product":"NetApp VASA Provider for Clustered Data ONTAP 6.x"},{"burt":"883989","jira":"","product":"NetApp VTL"},{"burt":"883975","jira":"","product":"OnCommand Balance"},{"burt":"883980","jira":"","product":"OnCommand Performance Manager (Unified Manager Performance Pkg)"},{"burt":"883979","jira":"","product":"OnCommand Unified Manager for Clustered Data ONTAP"},{"burt":"883974","jira":"","product":"RapidData Migration Solution"},{"burt":"883973","jira":"","product":"Service Processor"},{"burt":"885159","jira":"","product":"Single Mailbox Recovery"},{"burt":"883981","jira":"","product":"SnapDrive for Unix"},{"burt":"885160","jira":"","product":"SnapProtect"},{"burt":"883985","jira":"","product":"StorageGRID (formerly StorageGRID Webscale)"},{"burt":"883984","jira":"","product":"StorageGRID9 (9.x and prior)"}],"kb_investigating_list":[],"kb_num":"9010027","kb_ref":["http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0235","http://www.openwall.com/lists/oss-security/2015/01/27/9","https://community.qualys.com/blogs/laws-of-vulnerabilities/2015/01/27/the-ghost-vulnerability"],"kb_rev_history":[{"comment":"Initial Public Release","date":"20150127","version":"1.0"},{"comment":"Updated Software Versions and Fixes & Affected Products","date":"20150128","version":"2.0"},{"comment":"Updated Affected Products","date":"20150128","version":"3.0"},{"comment":"Updated Affected Products; Summary reworded","date":"20150128","version":"4.0"},{"comment":"Updated Affected Products, Products Not Affected, & Products With Revised Vulnerability Status","date":"20150129","version":"5.0"},{"comment":"Updated Products With Revised Vulnerability Status & Affected Products; Removed QLogic switch due to EOS","date":"20150130","version":"6.0"},{"comment":"Updated Affected Products, Products Not Affected, & Products With Revised Vulnerability Status","date":"20150202","version":"7.0"},{"comment":"Updated Affected Products & Products With Revised Vulnerability Status","date":"20150203","version":"8.0"},{"comment":"Removed erroneously included component level products","date":"20150204","version":"9.0"},{"comment":"Updated Products Not Affected","date":"20150209","version":"10.0"},{"comment":"Updated Products Not Affected & Software Versions and Fixes; moved RapidData Migration from Affected Products to Solution Products With Revised Vulnerability Status","date":"20150210","version":"11.0"},{"comment":"Updated Affected Products","date":"20150211","version":"12.0"},{"comment":"Corrected ID link","date":"20150217","version":"13.0"},{"comment":"Updated Affected Products","date":"20150227","version":"14.0"},{"comment":"Updated Software Versions and Fixes","date":"20150313","version":"15.0"},{"comment":"Updated Products With Revised Vulnerability Status","date":"20150320","version":"16.0"},{"comment":"Updated Software Versions and Fixes","date":"20150409","version":"17.0"},{"comment":"Added Cluster Network/Management Switches (Cisco) to Software Versions and Fixes","date":"20150626","version":"18.0"},{"comment":"Cisco Data Center Network Manager moved to Products With Revised Vulnerability Status; Cisco MDS, Cisco Nexus 5k/6k, Cisco Data Center Network Manager, NetApp VASA Provider for Clustered Data ONTAP added to Software Versions and Fixes","date":"20160823","version":"19.0"},{"comment":"Fibre Channel Switch (Cisco) moved to Affected Products, Final status","date":"20170221","version":"20.0"},{"comment":"SolidFire Element OS moved to Products Not Affected","date":"20180320","version":"21.0"}],"kb_revised_list":[],"kb_scoring":{"":"CVSS:2.0/AV:N/AC:M/Au:N/C:C/I:C/A:C/E:POC/RL:U/RC:C"},"kb_scoring_calc":[{"cve_id":"","range":"HIGH","score":8.4,"vector":"AV:N/AC:M/Au:N/C:C/I:C/A:C/E:POC/RL:U/RC:C"}],"kb_status":"Final","kb_summary":"A vulnerability known as GHOST may affect multiple NetApp products and the impact is under investigation. GNU C Library (glibc) versions up to glibc-2.18 are susceptible to a vulnerability in the gethostbyname*() function potentially leading to arbitrary code execution.","kb_title":"CVE-2015-0235 GNU C Library (glibc) Vulnerability in Multiple NetApp Products","kb_unaffected_list":["7-Mode Transition Tool","ATTO FibreBridge - 6500N","Brocade Fabric Operating System Firmware","Brocade Network Advisor Software","Cloud Manager","Cluster Network Switch (NetApp CN1610)","Clustered Data ONTAP","Clustered Data ONTAP Antivirus Connector","Data ONTAP Edge","E-Series SANtricity Storage Manager","E-Series SANtricity Web Services (REST API) for Web Services Proxy","FAS/AFF BIOS","Host Utilities - SAN for Linux","Host Utilities - SAN for Windows","NetApp Cloud Backup (formerly AltaVault)","NetApp Manageability SDK","NetApp NFS Plug-in for VMware VAAI","NetApp SANtricity SMI-S Provider","NetApp SMI-S Provider","NetApp SolidFire, Enterprise SDS & HCI Storage Node (Element Software)","NetApp Storage Encryption","OnCommand Insight","OnCommand Performance Manager (Unified Manager Performance Pkg)","OnCommand Unified Manager for Clustered Data ONTAP","OnCommand Workflow Automation","Open Systems SnapVault Agent","Service Processor","Single Mailbox Recovery","Snap Creator Framework","SnapManager for Exchange","SnapManager for Hyper-V","SnapManager for Oracle","SnapManager for SAP","SnapManager for Sharepoint","Storage Services Connector","System Manager 9.x"],"kb_workarounds":"<ul><li>StorageGRID/StorageGRID Webscale - Applying Novell SLES Security Patches <a href=\"https://kb.netapp.com/support/index?page=content&amp;id=1014874\" target=\"_blank\">https://kb.netapp.com/support/index?page=content&amp;id=1014874</a></li></ul>","ntap_advisory_id":"NTAP-20150127-0001","adv_id":"ntap-20150127-0001","published_date":"2015-01-27T00:00:00","updated_date":"2018-03-20T00:00:00","inserted_date":"2025-05-27T05:01:19.901000","modified_date":null}}