First published: Thu Feb 10 2011(Updated: )
Stack-based buffer overflow in BMC PATROL Agent Service Daemon for in Performance Analysis for Servers, Performance Assurance for Servers, and Performance Assurance for Virtual Servers 7.4.00 through 7.5.10; Performance Analyzer and Performance Predictor for Servers 7.4.00 through 7.5.10; and Capacity Management Essentials 1.2.00 (7.4.15) allows remote attackers to execute arbitrary code via a crafted length value in a BGS_MULTIPLE_READS command to TCP port 6768.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
BMC Performance Analysis for Servers | =7.4.00 | |
BMC Performance Analysis for Servers | =7.4.10 | |
BMC Performance Analysis for Servers | =7.4.15 | |
BMC Performance Analysis for Servers | =7.5.00 | |
BMC Performance Analysis for Servers | =7.5.10 | |
BMC Performance Assurance for Servers | =7.4.00 | |
BMC Performance Assurance for Servers | =7.4.10 | |
BMC Performance Assurance for Servers | =7.4.15 | |
BMC Performance Assurance for Servers | =7.5.00 | |
BMC Performance Assurance for Servers | =7.5.10 | |
BMC Performance Assurance for Virtual Servers | =7.4.00 | |
BMC Performance Assurance for Virtual Servers | =7.4.10 | |
BMC Performance Assurance for Virtual Servers | =7.4.15 | |
BMC Performance Assurance for Virtual Servers | =7.5.00 | |
BMC Performance Assurance for Virtual Servers | =7.5.10 | |
BMC Performance Analysis for Servers | =7.4.00 | |
BMC Performance Analysis for Servers | =7.4.10 | |
BMC Performance Analysis for Servers | =7.4.15 | |
BMC Performance Analysis for Servers | =7.5.00 | |
BMC Performance Analysis for Servers | =7.5.10 | |
BMC Performance Predictor for Servers | =7.4.00 | |
BMC Performance Predictor for Servers | =7.4.10 | |
BMC Performance Predictor for Servers | =7.4.15 | |
BMC Performance Predictor for Servers | =7.5.00 | |
BMC Performance Predictor for Servers | =7.5.10 | |
BMC Capacity Management Essentials | =1.2.00 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-0975 has a high severity rating due to its potential for stack-based buffer overflow, which can lead to arbitrary code execution.
To fix CVE-2011-0975, you should update affected BMC software products to versions that are not impacted by this vulnerability.
CVE-2011-0975 affects BMC PATROL Agent Service Daemon and several versions of Performance Analysis for Servers, Performance Assurance for Servers, and Performance Predictor for Servers.
The impacts of CVE-2011-0975 can include unauthorized access, system crashes, or running arbitrary code due to the buffer overflow vulnerability.
As of now, there are no reported active exploits for CVE-2011-0975, but users should remain vigilant and apply patches promptly.