IBM WebSM Lets Remote Users Deny Service
|
|
SecurityTracker Alert ID: 1018178 |
|
SecurityTracker URL: http://securitytracker.com/id/1018178
|
|
CVE Reference:
CVE-2007-2995
(Links to External Site)
|
Updated: May 12 2008
|
Original Entry Date: May 31 2007
|
Impact:
Denial of service via network
|
Fix Available: Yes Vendor Confirmed: Yes
|
|
Description:
A vulnerability was reported in IBM WebSM. A remote user can cause denial of service conditions.
A remote user can send specially crafted data to consume all available memory on the target system.
WebSM is affected when configured in client-server mode, applet mode, or remote client mode. WebSM is not affected when configured in standalone application mode.
|
Impact:
A remote user can consume all available system memory.
|
Solution:
IBM has provided the following fixes:
APAR number for AIX 5200-09: IY95637 (available)
APAR number for AIX 5300-05: IY95526 (available approx. 05/23/07)
Interim fixes are available at:
ftp://aix.software.ibm.com/aix/efixes/security/websm_ifix.tar.Z
|
Vendor URL: www.ibm.com/ (Links to External Site)
|
Cause:
Not specified
|
Underlying OS: UNIX (AIX)
|
|
Message History:
None.
|
Source Message Contents
|
|
|
[Original Message Not Available for Viewing]
|
|