First published: Wed Jan 23 2008(Updated: )
Buffer overflow in the logging functionality of the HTTP server in IBM Tivoli Provisioning Manager for OS Deployment (TPMfOSD) before 5.1.0.3 Interim Fix 3 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via an HTTP request with a long method string to port 443/tcp.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ibm Tivoli Provisioning Manager Os Deployment | <=5.1.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-0401 is considered high severity due to its potential to allow remote code execution and denial of service attacks.
To mitigate CVE-2008-0401, you should upgrade IBM Tivoli Provisioning Manager for OS Deployment to version 5.1.0.3 Interim Fix 3 or later.
CVE-2008-0401 exploits a buffer overflow in the logging functionality of the HTTP server.
The impact of CVE-2008-0401 can lead to a denial of service from daemon crashes or potentially allow attackers to execute arbitrary code.
Systems running versions of IBM Tivoli Provisioning Manager for OS Deployment before 5.1.0.3 Interim Fix 3 remain vulnerable to CVE-2008-0401.