RSA Archer VRM OVA – Spectre and Meltdown Vulnerabilities (CVE-2017-5715, CVE-2017-5753, CVE-2017-5754)
Advisory Type
Security
Advisory Content
Article Number
000036184
CVE ID
000036184
Applies To
RSA Product Set: VRM
RSA Product/Service Type: VRM Virtual Images (OVA)
RSA Product/Service Type: VRM Virtual Images (OVA)
Article Summary
The VRM Virtual Image OVA is a single-user, root-user-only appliance. The vulnerabilities do not introduce any additional risk to a customer’s environment for “in-guest” attacks, provided the recommended best practices to protect the access of highly privileged accounts are followed. However, you should patch your VRM Virtual Images (CentOS Version 6) with latest kernel security update, which is currently available in the CentOS repository:
https://lists.centos.org/pipermail/centos-announce/2018-January/022701.html
https://lists.centos.org/pipermail/centos-announce/2018-January/022701.html
Link to Advisories
Resolution
The following rpm files from the CentOS file repository must be installed in each VRM warehouse node to apply the kernel patch:
Once the rpms are installed, you must reboot each warehouse node.
Another way to apply the security patches is to run this command on each node:
followed by a reboot on each node one by one.
Note: The VRM Virtual Images are configured with an internal network which will not have access to CentOS repository. Therefore, you should ask your IT department if there is an internal repository or a proxy server that you can use while you apply the patch.
- kernel-2.6.32-696.18.7.el6.x86_64.rpm
- kernel-abi-whitelists-2.6.32-696.18.7.el6.noarch.rpm
- kernel-debug-2.6.32-696.18.7.el6.x86_64.rpm
- kernel-debug-devel-2.6.32-696.18.7.el6.i686.rpm
- kernel-debug-devel-2.6.32-696.18.7.el6.x86_64.rpm
- kernel-devel-2.6.32-696.18.7.el6.x86_64.rpm
- kernel-doc-2.6.32-696.18.7.el6.noarch.rpm
- kernel-firmware-2.6.32-696.18.7.el6.noarch.rpm
- kernel-headers-2.6.32-696.18.7.el6.x86_64.rpm
- perf-2.6.32-696.18.7.el6.x86_64.rpm
- python-perf-2.6.32-696.18.7.el6.x86_64.rpm
- kernel-2.6.32-696.18.7.el6.i686.rpm
- kernel-abi-whitelists-2.6.32-696.18.7.el6.noarch.rpm
- kernel-debug-2.6.32-696.18.7.el6.i686.rpm
- kernel-debug-devel-2.6.32-696.18.7.el6.i686.rpm
- kernel-devel-2.6.32-696.18.7.el6.i686.rpm
- kernel-doc-2.6.32-696.18.7.el6.noarch.rpm
- kernel-firmware-2.6.32-696.18.7.el6.noarch.rpm
- kernel-headers-2.6.32-696.18.7.el6.i686.rpm
- perf-2.6.32-696.18.7.el6.i686.rpm
- python-perf-2.6.32-696.18.7.el6.i686.rpm
Once the rpms are installed, you must reboot each warehouse node.
Another way to apply the security patches is to run this command on each node:
Note: The VRM Virtual Images are configured with an internal network which will not have access to CentOS repository. Therefore, you should ask your IT department if there is an internal repository or a proxy server that you can use while you apply the patch.