AR# 66709


2015.4 Licensing - Flex Publisher Security vulnerability CVE-2015-8277 - Does Xilinx have updated Licensing utilities?


In January 2016, Flexera acknowledged a security vulnerability referred to as CVE-2015-8277 which exists in the FlexNet Publisher (FNP) server components.

  • What is the extent of the vulnerability?
  • Does this effect Xilinx licensing utilities?
  • If so, are there updated license utilities available?
  • Are there draw-backs or other considerations that need to be addressed when upgrading to the latest version of FlexLM utilities?


What is the extent of the vulnerability?

Xilinx was not provided with full details on the vulnerability but we do know the following:

  • If you are not running a license server, you are not at risk.
  • The vulnerability was rated as High
  • These vulnerabilities exist on all platforms in all supported versions of the following FlexNet Publisher components:
  • The vulnerability affects lmgrd and vendor daemon executables built by each FlexNet Publisher customer from object code provided by Flexera Software
  • Vulnerability is greater if the application is directly exposed to the internet.
  • If your license servers are behind a firewall, the risk is reduced.

The Base CVSS score is 7.6.
Only under highly-customized environments would a user of FlexNet-licensed software expose the lmgrd or vendor daemon executables to the internet.
If a user exposes either of these components to the internet, then a partial work-around is to expose them to only a trusted network until they can be patched.
Exposing either of these components to the internet raises the CVSS base score of this vulnerability to 9.0.

Are Xilinx License tools affected?

Yes, this issue affects the following:

  • The lmgrd executable (versions earlier than v11.13.1.2),
  • Vendor daemon executables, including xilinxd, built by each FlexNet Publisher customer from object code provided by Flexera Software (versions earlier than v11.13.1.2).

Are updated License utilities available?

Xilinx has built license utilities based on FNP v11.13.1.3.

The license utilities are attached to this answer record for Windows and Linux platforms.

The following issues should be noted before using the v11.13.1.3 utilities.

  • Red Hat Enterprise Linux 5 (RHEL 5) is no longer officially supported by Flexera as a license server platform with FNP v11.13.1.2 or later server components. However, initial Red Hat Enterprise 5 testing by Xilinx has not highlighted any problems with the FNP v11.13.1.2 license server components.
    Please note, RHEL 5 is still fully supported for the licensing runtime (client applications are unaffected).
  • Serving an activation license with v11.13.1.3 trusted storage and v11.13.1.3 lmgrd causes the license to become untrusted. See (Xilinx Answer 66899).

Xilinx recommends that you update your license server software or make sure your license servers are behind a firewall. Updated components lmgrd and xilinxd must both be v11.13.1.3 or higher in order to eliminate this vulnerability.

License Administrator Best Practices for Mitigating Risk Exposure:

The following steps are recommended by Flexera as License Administrator best practices to help protect against this and other security vulnerabilities:

  • Launch lmgrd and vendor daemon executables using a least privileged security level.
  • Use the recommended security settings offered by the Operating System (OS) vendors that resist buffer/stack overflow attacks.
    For example, the Data Execution Prevention (DEP) feature on Windows helps in this regard. Most OS updates also include security features that take advantage of both hardware and software based protection mechanisms against malicious code execution.
  • Limit access to only administrative users by launching lmgrd with the '-2 p' command-line option, unless you are using FlexNet Manager for Engineering Applications. Refer to the product documentation for limitations related to usage of this command-line option.
  • Do not use the default 27000-27009 TCP ports for lmgrd (Note: This only inhibits a hacker who does not use an intelligent port scanning tool).

The updated license utilities (v11.13.1.3) are in included with Vivado 2016.1. I.


Associated Attachments

Name File Size File Type 23 MB ZIP 21 MB ZIP
AR# 66709
Date 02/21/2017
Status Active
Type Known Issues
People Also Viewed