IBM Tivoli Monitoring Express Universal Agent Multiple Heap Buffer Overflow Vulnerabilities
BID:23558
Info
IBM Tivoli Monitoring Express Universal Agent Multiple Heap Buffer Overflow Vulnerabilities
| Bugtraq ID: | 23558 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2007-2137 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 18 2007 12:00AM |
| Updated: | Jul 09 2007 08:07PM |
| Credit: | CIRT.DK is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
IBM Tivoli Monitoring Express 6.1 |
| Not Vulnerable: | |
Discussion
IBM Tivoli Monitoring Express Universal Agent Multiple Heap Buffer Overflow Vulnerabilities
IBM Tivoli Monitoring Express Universal Agent is prone to multiple buffer-overflow vulnerabilities because the application fails to bounds-check user-supplied data before copying it into an insufficiently sized memory buffer.
An attacker can exploit these issues to execute arbitrary code within the context of the vulnerable application. This may facilitate the compromise of affected servers. To leverage these issues, the attacker does not need to authenticate.
IBM Tivoli Monitoring Express 6.1 is affected.
IBM Tivoli Monitoring Express Universal Agent is prone to multiple buffer-overflow vulnerabilities because the application fails to bounds-check user-supplied data before copying it into an insufficiently sized memory buffer.
An attacker can exploit these issues to execute arbitrary code within the context of the vulnerable application. This may facilitate the compromise of affected servers. To leverage these issues, the attacker does not need to authenticate.
IBM Tivoli Monitoring Express 6.1 is affected.
Exploit / POC
IBM Tivoli Monitoring Express Universal Agent Multiple Heap Buffer Overflow Vulnerabilities
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Solution / Fix
IBM Tivoli Monitoring Express Universal Agent Multiple Heap Buffer Overflow Vulnerabilities
Solution:
IBM has released version 6.1.0 Fix Pack 2 to address these issues. Please see the vendor references for more information.
Solution:
IBM has released version 6.1.0 Fix Pack 2 to address these issues. Please see the vendor references for more information.
References
IBM Tivoli Monitoring Express Universal Agent Multiple Heap Buffer Overflow Vulnerabilities
References:
References: