CVE-2009-3089: Null Pointer Dereference
IBM Tivoli Directory Server (TDS) 6.0 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via unspecified vectors, related to (1) the ibmslapd.exe daemon on Windows and (2) the ibmdiradm daemon in the administration server on Linux, as demonstrated by certain modules in VulnDisco Pack Professional 8.11, a different vulnerability than CVE-2006-0717. NOTE: as of 20090903, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-3089?
CVE-2009-3089 is classified as a high-severity vulnerability due to its potential to cause a denial of service.
How do I fix CVE-2009-3089?
To fix CVE-2009-3089, update your IBM Tivoli Directory Server to a version that addresses this vulnerability.
What causes the denial of service in CVE-2009-3089?
CVE-2009-3089 causes denial of service through a NULL pointer dereference in the ibmslapd.exe and ibmdiradm daemons.
Is CVE-2009-3089 exploitable remotely?
Yes, CVE-2009-3089 can be exploited remotely by attackers targeting vulnerable instances of IBM Tivoli Directory Server 6.0.
Which versions of IBM Tivoli Directory Server are affected by CVE-2009-3089?
CVE-2009-3089 specifically affects IBM Tivoli Directory Server version 6.0.