IBM Tivoli Directory Server Unspecified LDAP Memory Corruption Vulnerability
BID:16593
Info
IBM Tivoli Directory Server Unspecified LDAP Memory Corruption Vulnerability
| Bugtraq ID: | 16593 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 11 2006 12:00AM |
| Updated: | Feb 13 2006 05:48PM |
| Credit: | Discovery is credited to Evgeny Legerov. |
| Vulnerable: |
IBM Directory Server 6.0 .0 |
| Not Vulnerable: | |
Discussion
IBM Tivoli Directory Server Unspecified LDAP Memory Corruption Vulnerability
IBM Tivoli Directory Server is prone to an unspecified memory corruption. This issue may be triggered by malformed LDAP data.
The exact impact of this vulnerability is not known at this time. Although the issue is known to crash the server, the possibility of remote code execution is unconfirmed.
The vulnerability was reported for version 6.0 on the Linux platform. Other versions or platforms are not known to be affected.
This vulnerability will be updated as further information is made available.
IBM Tivoli Directory Server is prone to an unspecified memory corruption. This issue may be triggered by malformed LDAP data.
The exact impact of this vulnerability is not known at this time. Although the issue is known to crash the server, the possibility of remote code execution is unconfirmed.
The vulnerability was reported for version 6.0 on the Linux platform. Other versions or platforms are not known to be affected.
This vulnerability will be updated as further information is made available.
Exploit / POC
IBM Tivoli Directory Server Unspecified LDAP Memory Corruption Vulnerability
This issue can be reproduced by running the following command for the ProtoVer Sample LDAP testsuite:
./run.py localhost 389 2532 1
This issue can be reproduced by running the following command for the ProtoVer Sample LDAP testsuite:
./run.py localhost 389 2532 1
Solution / Fix
IBM Tivoli Directory Server Unspecified LDAP Memory Corruption Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
References
IBM Tivoli Directory Server Unspecified LDAP Memory Corruption Vulnerability
References:
References:
- [Dailydave] IBM Tivoli Directory Server 0day (Evgeny Legerov)
- ProtoVer Sample LDAP testsuite (Gleg Ltd)