Tivoli Provisioning Manager for OS Deployment HTTP server buffer overflow
Added: 01/28/2008CVE: CVE-2008-0401
BID: 27387
OSVDB: 40481
Background
Tivoli Provisioning Manager for OS Deployment is a product which facilitates remote operating system installation and management.Problem
A buffer overflow vulnerability in the HTTP server which comes with Tivoli Provisioning Manager for OS Deployment allows remote attackers to execute arbitrary commands by sending a request for a long, specially crafted URL.Resolution
Apply Interim Fix 3, Version 5.1.0.3.References
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=647Limitations
Exploit works on Tivoli Provisioning Manager for OS Deployment 5.1.0.2.Exploit requires the IO-Socket-SSL PERL module to be installed on the scanning host. This module is available from http://www.cpan.org/modules/by-module/IO/.
Platforms
Windows 2000Windows Server 2003
Back to exploit index