IBM Tivoli Directory Server Zero-Byte Write Error Lets Remote Users Deny Service
|
|
SecurityTracker Alert ID: 1015653
|
|
SecurityTracker URL: http://securitytracker.com/id?1015653
|
|
CVE Reference: CVE-2006-0717
(Links to External Site)
|
Date: Feb 21 2006
|
Impact: Denial of service via network
|
Exploit Included: Yes
Vendor Confirmed: Yes
|
Version(s): 4.1, 5.1, 5.2, 6.0
|
Description: A vulnerability was reported in IBM Tivoli Directory Server. A remote user can cause denial of service conditions.
A remote user can send a specially crafted request to cause the target service to write to a zero-byte length buffer and crash.
The
flaw can be triggered with the following command using the ProtoVer Sample LDAP test suite (http://www.gleg.net/protover_ldap_sample.shtml):
./run.py
localhost 389 2532 1
Evgeny Legerov on gleg.net discovered this vulnerability.
|
Impact: A remote user can cause the target service to crash.
|
Solution: No solution was available at the time of this entry. IBM has developed a fix which will be available within approximately one week
after testing is completed.
The vendor's advisory is available at:
http://www-1.ibm.com/support/docview.wss?uid=swg21230820
|
Vendor URL: www-1.ibm.com/support/docview.wss?uid=swg21230820 (Links to External Site)
|
Cause: Exception handling error
|
Underlying OS: Linux (Any), UNIX (AIX), UNIX (HP/UX), UNIX (Solaris - SunOS), Windows (2000)
|
|
Message History:
None.
|
Source Message Contents
|
Date: Tue, 21 Feb 2006 09:18:00 -0500
Subject: Malformed LDAP request will abnormally terminate the IBM Tivoli Directory Server.
|
http://www-1.ibm.com/support/docview.wss?uid=swg21230820
|
|