Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 145615 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.902507
Kategorie:Buffer overflow
Titel:IBM Tivoli Directory Server SASL Bind Request RCE Vulnerability
Zusammenfassung:IBM Tivoli Directory Server is prone to a remote code execution (RCE) vulnerability.
Beschreibung:Summary:
IBM Tivoli Directory Server is prone to a remote code execution (RCE) vulnerability.

Vulnerability Insight:
The flaw is caused by a stack overflow error in the 'ibmslapd.exe' component
when allocating a buffer via the 'ber_get_int()' function within
'libibmldap.dll' while handling LDAP CRAM-MD5 packets, which could be
exploited by remote unauthenticated attackers to execute arbitrary code with
SYSTEM privileges.

Vulnerability Impact:
Successful exploitation could allow remote attackers to execute arbitrary
code within the context of the affected application or retrieve potentially sensitive information.

Affected Software/OS:
IBM Tivoli Directory Server 5.2 before 5.2.0.5-TIV-ITDS-IF0010,
6.0 before 6.0.0.67 (6.0.0.8-TIV-ITDS-IF0009),
6.1 before 6.1.0.40 (6.1.0.5-TIV-ITDS-IF0003),
6.2 before 6.2.0.16 (6.2.0.3-TIV-ITDS-IF0002),
and 6.3 before 6.3.0.3

Solution:
Apply Vendor patches.

CVSS Score:
10.0

CVSS Vector:
AV:N/AC:L/Au:N/C:C/I:C/A:C

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2011-1206
AIX APAR: IO14009
http://www.ibm.com/support/docview.wss?uid=swg1IO14009
AIX APAR: IO14010
http://www.ibm.com/support/docview.wss?uid=swg1IO14010
AIX APAR: IO14013
http://www.ibm.com/support/docview.wss?uid=swg1IO14013
AIX APAR: IO14045
http://www.ibm.com/support/docview.wss?uid=swg1IO14045
AIX APAR: IO14046
http://www.ibm.com/support/docview.wss?uid=swg1IO14046
http://securitytracker.com/id?1025358
http://secunia.com/advisories/44184
http://securityreason.com/securityalert/8213
XForce ISS Database: ibm-tds-ibmslapd-bo(66711)
https://exchange.xforce.ibmcloud.com/vulnerabilities/66711
Common Vulnerability Exposure (CVE) ID: CVE-2011-1820
AIX APAR: IO14023
http://www.ibm.com/support/docview.wss?uid=swg1IO14023
AIX APAR: IO14025
http://www.ibm.com/support/docview.wss?uid=swg1IO14025
AIX APAR: IO14028
http://www.ibm.com/support/docview.wss?uid=swg1IO14028
AIX APAR: IO14043
http://www.ibm.com/support/docview.wss?uid=swg1IO14043
AIX APAR: IO14044
http://www.ibm.com/support/docview.wss?uid=swg1IO14044
XForce ISS Database: ibm-tds-proxyserver-info-disclosure(66712)
https://exchange.xforce.ibmcloud.com/vulnerabilities/66712
CopyrightCopyright (C) 2011 Greenbone AG

Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.