CVE-2011-1385: High severity ibm virtual i/o server (vios) vulnerability
IBM AIX 5.3, 6.1, and 7.1, and VIOS 2.1.x and 2.2.x, allows remote attackers to cause a denial of service (system crash) via an ICMP Echo Reply packet that contains 1 in the Identifier field, a different vulnerability than CVE-2012-0194.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2011-1385?
CVE-2011-1385 is classified as a denial of service vulnerability that can lead to a system crash.
How do I fix CVE-2011-1385?
To fix CVE-2011-1385, apply available patches provided by IBM for the affected versions of AIX and VIOS.
Which versions of IBM AIX are affected by CVE-2011-1385?
CVE-2011-1385 affects IBM AIX versions 5.3, 6.1, and 7.1.
Which versions of VIOS are impacted by CVE-2011-1385?
CVE-2011-1385 impacts IBM VIOS versions 2.1.x and 2.2.x, specifically 2.1.0.0, 2.1.2.10, 2.1.2.12, 2.1.2.13, 2.1.3.10, 2.2.0.10, 2.2.0.11, 2.2.0.12, 2.2.0.13, 2.2.1.0, 2.2.1.1, 2.2.1.3.
What type of attack does CVE-2011-1385 enable?
CVE-2011-1385 enables remote attackers to perform denial of service attacks through specially crafted ICMP Echo Reply packets.