CVE-2011-0310: Buffer Overflow
Published Jan 13, 2011
·Updated
Buffer overflow in IBM WebSphere MQ 7.0 before 7.0.1.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted header field in a message.
Affected Software
7 affected components
IBM WebSphere MQ=7.0.1.2
IBM WebSphere MQ=7.0.1.3
IBM WebSphere MQ=7.0.0.1
IBM WebSphere MQ=7.0.0.2
IBM WebSphere MQ=7.0.1.1
IBM WebSphere MQ=7.0
IBM WebSphere MQ=7.0.1.0
Event History
Jan 13, 2011
CVE Published
via MITRE·06:35 PM
Data Sourced
via MITRE·06:35 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-0310?
CVE-2011-0310 is classified as a critical vulnerability due to its potential to allow remote code execution and denial of service.
2
How do I fix CVE-2011-0310?
To fix CVE-2011-0310, upgrade IBM WebSphere MQ to version 7.0.1.4 or later.
3
What versions of IBM WebSphere MQ are affected by CVE-2011-0310?
CVE-2011-0310 affects IBM WebSphere MQ versions 7.0, 7.0.0.1, 7.0.0.2, 7.0.1.0, 7.0.1.1, 7.0.1.2, and 7.0.1.3.
4
What type of attack can exploit CVE-2011-0310?
CVE-2011-0310 can be exploited through a crafted header field in a message which can lead to execution of arbitrary code.
5
Is there a risk of denial of service with CVE-2011-0310?
Yes, CVE-2011-0310 can lead to a denial of service condition by causing the application to crash.