First published: Thu Apr 21 2011(Updated: )
Stack-based buffer overflow in the server process in ibmslapd.exe in IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-IF0010, 6.0 before 6.0.0.67 (aka 6.0.0.8-TIV-ITDS-IF0009), 6.1 before 6.1.0.40 (aka 6.1.0.5-TIV-ITDS-IF0003), 6.2 before 6.2.0.16 (aka 6.2.0.3-TIV-ITDS-IF0002), and 6.3 before 6.3.0.3 (aka 6.3.0.0-TIV-ITDS-IF0003) allows remote attackers to execute arbitrary code via a crafted LDAP request. NOTE: some of these details are obtained from third party information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Tivoli Directory Server | =5.2.0 | |
IBM Tivoli Directory Server | =5.2.0.4 | |
IBM Tivoli Directory Server | =6.0.0.14 | |
IBM Tivoli Directory Server | =6.0.0.61 | |
IBM Tivoli Directory Server | =6.0.0.64 | |
IBM Tivoli Directory Server | =6.0.0.53 | |
IBM Tivoli Directory Server | =6.0.0.54 | |
IBM Tivoli Directory Server | =6.0.0.0 | |
IBM Tivoli Directory Server | =6.0.0.62 | |
IBM Tivoli Directory Server | =6.0.0.56 | |
IBM Tivoli Directory Server | =6.0.0.1 | |
IBM Tivoli Directory Server | =6.0.0.65 | |
IBM Tivoli Directory Server | =6.0.0.7 | |
IBM Tivoli Directory Server | =6.0.0.45 | |
IBM Tivoli Directory Server | =6.0.0.33 | |
IBM Tivoli Directory Server | =6.0.0.52 | |
IBM Tivoli Directory Server | =6.0 | |
IBM Tivoli Directory Server | =6.0.0.55 | |
IBM Tivoli Directory Server | =6.0.0.8 | |
IBM Tivoli Directory Server | =6.0.0.59 | |
IBM Tivoli Directory Server | =6.0.0.57 | |
IBM Tivoli Directory Server | =6.0.0.58 | |
IBM Tivoli Directory Server | =6.0.0.60 | |
IBM Tivoli Directory Server | =6.0.0.63 | |
IBM Tivoli Directory Server | =6.0.0.66 | |
IBM Tivoli Directory Server | =6.0.0.41 | |
IBM Tivoli Directory Server | =6.0.0.19 | |
IBM Tivoli Directory Server | =6.1.0.13 | |
IBM Tivoli Directory Server | =6.1.0.8 | |
IBM Tivoli Directory Server | =6.1.0.36 | |
IBM Tivoli Directory Server | =6.1.0.20 | |
IBM Tivoli Directory Server | =6.1.0.9 | |
IBM Tivoli Directory Server | =6.1.0.35 | |
IBM Tivoli Directory Server | =6.1.0.23 | |
IBM Tivoli Directory Server | =6.1.0.22 | |
IBM Tivoli Directory Server | =6.1.0.32 | |
IBM Tivoli Directory Server | =6.1.0.25 | |
IBM Tivoli Directory Server | =6.1.0.3 | |
IBM Tivoli Directory Server | =6.1.0.38 | |
IBM Tivoli Directory Server | =6.1.0.14 | |
IBM Tivoli Directory Server | =6.1.0.19 | |
IBM Tivoli Directory Server | =6.1.0.17 | |
IBM Tivoli Directory Server | =6.1.0.1 | |
IBM Tivoli Directory Server | =6.1.0.11 | |
IBM Tivoli Directory Server | =6.1.0.6 | |
IBM Tivoli Directory Server | =6.1.0.0 | |
IBM Tivoli Directory Server | =6.1.0.39 | |
IBM Tivoli Directory Server | =6.1.0.10 | |
IBM Tivoli Directory Server | =6.1.0.27 | |
IBM Tivoli Directory Server | =6.1.0.33 | |
IBM Tivoli Directory Server | =6.1.0.2 | |
IBM Tivoli Directory Server | =6.1.0.26 | |
IBM Tivoli Directory Server | =6.1.0.24 | |
IBM Tivoli Directory Server | =6.1.0.5 | |
IBM Tivoli Directory Server | =6.1.0.30 | |
IBM Tivoli Directory Server | =6.1.0.21 | |
IBM Tivoli Directory Server | =6.1.0.18 | |
IBM Tivoli Directory Server | =6.1.0.4 | |
IBM Tivoli Directory Server | =6.1.0.37 | |
IBM Tivoli Directory Server | =6.1.0.12 | |
IBM Tivoli Directory Server | =6.1.0.15 | |
IBM Tivoli Directory Server | =6.1.0.28 | |
IBM Tivoli Directory Server | =6.1.0.29 | |
IBM Tivoli Directory Server | =6.1.0.7 | |
IBM Tivoli Directory Server | =6.1.0.34 | |
IBM Tivoli Directory Server | =6.1.0.31 | |
IBM Tivoli Directory Server | =6.2.0.3 | |
IBM Tivoli Directory Server | =6.2.0.7 | |
IBM Tivoli Directory Server | =6.2.0.6 | |
IBM Tivoli Directory Server | =6.2.0.8 | |
IBM Tivoli Directory Server | =6.2.0.12 | |
IBM Tivoli Directory Server | =6.2.0.5 | |
IBM Tivoli Directory Server | =6.2.0.10 | |
IBM Tivoli Directory Server | =6.2.0.11 | |
IBM Tivoli Directory Server | =6.2.0.14 | |
IBM Tivoli Directory Server | =6.2.0.13 | |
IBM Tivoli Directory Server | =6.2.0.4 | |
IBM Tivoli Directory Server | =6.2.0.0 | |
IBM Tivoli Directory Server | =6.2.0.1 | |
IBM Tivoli Directory Server | =6.2.0.2 | |
IBM Tivoli Directory Server | =6.2.0.15 | |
IBM Tivoli Directory Server | =6.3.0.0 | |
IBM Tivoli Directory Server | =6.3.0.2 | |
IBM Tivoli Directory Server | =6.3.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-1206 has a high severity rating due to its potential for stack-based buffer overflow attacks.
To fix CVE-2011-1206, you should upgrade to the patched version of IBM Tivoli Directory Server 5.2.0.5 or 6.0.0.67 and later.
CVE-2011-1206 affects IBM Tivoli Directory Server versions 5.2 prior to 5.2.0.5, all 6.0 versions prior to 6.0.0.67, along with certain 6.1, 6.2, and 6.3 versions.
Yes, CVE-2011-1206 can be exploited remotely, allowing attackers to execute arbitrary code on the affected systems.
Yes, it is recommended to stop the IBM Tivoli Directory Server services before applying the patch for CVE-2011-1206.