Vulnerability Name: | CVE-2005-2170 (CCN-21351) | ||||||||
Assigned: | 2005-07-11 | ||||||||
Published: | 2005-07-11 | ||||||||
Updated: | 2011-03-08 | ||||||||
Summary: | The LCF component (lcfd) in IBM Tivoli Management Framework Endpoint allows remote attackers to cause a denial of service (process exit and connection loss) by connecting to LCF and ending the connection without sending any data. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
| ||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Denial of Service | ||||||||
References: | Source: MITRE Type: CNA CVE-2005-2170 Source: CCN Type: SA15953 IBM Tivoli Management Framework Endpoint Denial of Service Source: SECUNIA Type: Patch, Vendor Advisory 15953 Source: CCN Type: SECTRACK ID: 1014424 Tivoli Management Framework Endpoint Service (lcfd) Lets Remote Users Deny Service Source: SECTRACK Type: UNKNOWN 1014424 Source: CCN Type: IBM Support and Download Web page Tivoli Framework Patch 4.1.1-LCF-0020 Source: CONFIRM Type: Patch, Vendor Advisory http://www-1.ibm.com/support/entdocview.wss?uid=swg21210334 Source: MISC Type: Vendor Advisory http://www.corsaire.com/advisories/c041127-001.txt Source: CCN Type: OSVDB ID: 17778 IBM Tivoli Management Framework Endpoint lcfd Process Connection Saturation DoS Source: BID Type: Patch 14194 Source: CCN Type: BID-14194 IBM Tivoli Management Framework Endpoint Remote Denial Of Service Vulnerability Source: CCN Type: Tivoli Web site Tivoli Management Framework Source: VUPEN Type: UNKNOWN ADV-2005-1018 Source: XF Type: UNKNOWN tivoli-endpoint-dos(21351) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |