CVE-2011-1206: Buffer Overflow
Stack-based buffer overflow in the server process in ibmslapd.exe in IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-IF0010, 6.0 before 6.0.0.67 (aka 6.0.0.8-TIV-ITDS-IF0009), 6.1 before 6.1.0.40 (aka 6.1.0.5-TIV-ITDS-IF0003), 6.2 before 6.2.0.16 (aka 6.2.0.3-TIV-ITDS-IF0002), and 6.3 before 6.3.0.3 (aka 6.3.0.0-TIV-ITDS-IF0003) allows remote attackers to execute arbitrary code via a crafted LDAP request. NOTE: some of these details are obtained from third party information.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2011-1206?
CVE-2011-1206 has a high severity rating due to its potential for stack-based buffer overflow attacks.
How do I fix CVE-2011-1206?
To fix CVE-2011-1206, you should upgrade to the patched version of IBM Tivoli Directory Server 5.2.0.5 or 6.0.0.67 and later.
What versions of IBM Tivoli Directory Server are affected by CVE-2011-1206?
CVE-2011-1206 affects IBM Tivoli Directory Server versions 5.2 prior to 5.2.0.5, all 6.0 versions prior to 6.0.0.67, along with certain 6.1, 6.2, and 6.3 versions.
Can CVE-2011-1206 be exploited remotely?
Yes, CVE-2011-1206 can be exploited remotely, allowing attackers to execute arbitrary code on the affected systems.
Is it necessary to stop services while applying the patch for CVE-2011-1206?
Yes, it is recommended to stop the IBM Tivoli Directory Server services before applying the patch for CVE-2011-1206.