IBM Tivoli Provisioning Manager for OS Deployment Divide By Zero Denial of Service Vulnerability
BID:24942
Info
IBM Tivoli Provisioning Manager for OS Deployment Divide By Zero Denial of Service Vulnerability
| Bugtraq ID: | 24942 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2007-3268 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 17 2007 12:00AM |
| Updated: | Jul 17 2007 12:00AM |
| Credit: | Manuel Santamarina Suarez is credited with the discovery of this vulnerability. |
| Vulnerable: |
IBM Tivoli Provisioning Manager for OS Deployment 5.1.0.2 |
| Not Vulnerable: |
IBM Tivoli Provisioning Manager for OS Deployment 5.1.Fix Pack 3 |
Discussion
IBM Tivoli Provisioning Manager for OS Deployment Divide By Zero Denial of Service Vulnerability
IBM Tivoli Provisioning Manager for OS Deployment is prone to a denial-of-service vulnerability because the server fails to handle exceptional conditions.
An attacker can exploit this issue to crash the affected server, denying service to legitimate users.
This issue is reported to affect IBM Tivoli Provisioning Manager for OS Deployment 5.1.0.2; other versions may be affected.
NOTE: The discoverer could not reproduce this vulnerability on IBM Tivoli Provisioning Manager for OS Deployment 5.1.0.116.
IBM Tivoli Provisioning Manager for OS Deployment is prone to a denial-of-service vulnerability because the server fails to handle exceptional conditions.
An attacker can exploit this issue to crash the affected server, denying service to legitimate users.
This issue is reported to affect IBM Tivoli Provisioning Manager for OS Deployment 5.1.0.2; other versions may be affected.
NOTE: The discoverer could not reproduce this vulnerability on IBM Tivoli Provisioning Manager for OS Deployment 5.1.0.116.
Exploit / POC
IBM Tivoli Provisioning Manager for OS Deployment Divide By Zero Denial of Service Vulnerability
An attacker can exploit this issue by using standard network utilities.
An attacker can exploit this issue by using standard network utilities.
Solution / Fix
IBM Tivoli Provisioning Manager for OS Deployment Divide By Zero Denial of Service Vulnerability
Solution:
The vendor released an update to address this issue. Please see the references for more information.
Solution:
The vendor released an update to address this issue. Please see the references for more information.
References
IBM Tivoli Provisioning Manager for OS Deployment Divide By Zero Denial of Service Vulnerability
References:
References:
- FP3 Tivoli Provisioning Manager for OS Deployment 5.1.0-TIV-TPMOSD-FP0003 (IBM)
- IBM Tivoli Provisioning Manager Express Homepage (IBM)
- iDefense Security Advisory 07.17.07: IBM Tivoli Provisioning Manager for OS Dep ([email protected])
- IBM Tivoli Provisioning Manager for OS Deployment TFTP Blocksize DoS Vulnerabili (iDefense Labs)