PT-2011-2948 · Ibm · Ibm Tivoli Directory Server

Francis Provencher

·

Publicado

2011-04-18

·

Atualizado

2017-08-17

·

CVE-2011-1206

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions IBM Tivoli Directory Server versions 5.2 through 5.2.0.5-TIV-ITDS-IF0010 IBM Tivoli Directory Server versions 6.0 through 6.0.0.67 IBM Tivoli Directory Server versions 6.1 through 6.1.0.40 IBM Tivoli Directory Server versions 6.2 through 6.2.0.16 IBM Tivoli Directory Server versions 6.3 through 6.3.0.3
Description A stack-based buffer overflow in the server process in ibmslapd.exe allows remote attackers to execute arbitrary code via a crafted LDAP request.
Recommendations For versions 5.2 through 5.2.0.5-TIV-ITDS-IF0010, update to version 5.2.0.5-TIV-ITDS-IF0010 or later. For versions 6.0 through 6.0.0.67, update to version 6.0.0.67 or later. For versions 6.1 through 6.1.0.40, update to version 6.1.0.40 or later. For versions 6.2 through 6.2.0.16, update to version 6.2.0.16 or later. For versions 6.3 through 6.3.0.3, update to version 6.3.0.3 or later.

Exploit

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2011-1206
ZDI-11-136

Produtos afetados

Ibm Tivoli Directory Server