Buffer Overflow in IBM Tivoli Provisioning Manager for OS Deployment
CVE-2008-0401

Currently unrated

Key Information:

Vendor
IBM
Vendor
CVE Published:
23 January 2008

Summary

A buffer overflow vulnerability exists in the logging functionality of the HTTP server in IBM Tivoli Provisioning Manager for OS Deployment. This flaw, present in versions prior to 5.1.0.3 Interim Fix 3, can be exploited by remote attackers through crafted HTTP requests containing excessively long method strings sent to port 443/tcp. Successful exploitation of this vulnerability could lead to a denial of service due to daemon crashes or, in some cases, allow attackers to execute arbitrary code on the affected system.

References

EPSS Score

28% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.