Vulnerability Name: | CVE-2011-1220 (CCN-67631) | ||||||||
Assigned: | 2011-05-25 | ||||||||
Published: | 2011-05-25 | ||||||||
Updated: | 2018-10-09 | ||||||||
Summary: | Stack-based buffer overflow in lcfd.exe in Tivoli Endpoint in IBM Tivoli Management Framework 3.7.1, 4.1, 4.1.1, and 4.3.1 allows remote authenticated users to execute arbitrary code via a long opts field. | ||||||||
CVSS v3 Severity: | 9.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 9.0 High (CVSS v2 Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C) 7.1 High (Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:OF/RC:C)
7.1 High (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-119 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2011-1220 Source: CCN Type: SA44628 IBM Tivoli Management Framework lcfd Endpoint Daemon Buffer Overflow Vulnerability Source: SECUNIA Type: Vendor Advisory 44628 Source: SREASON Type: UNKNOWN 8268 Source: SECTRACK Type: UNKNOWN 1025581 Source: CONFIRM Type: UNKNOWN http://www-01.ibm.com/support/docview.wss?uid=swg21499146 Source: AIXAPAR Type: UNKNOWN IZ90238 Source: CCN Type: OSVDB ID: 72713 IBM Tivoli Management Framework Endpoint lcfd.exe opts Field Overflow Source: CCN Type: OSVDB ID: 73223 IBM Tivoli Management Framework Endpoint Built-in Account Default HTTP Password Remote Restricted Page Access Source: BUGTRAQ Type: UNKNOWN 20110531 ZDI-11-169: IBM Tivoli Endpoint lcfd.exe opts Argument Remote Code Execution Vulnerability Source: CCN Type: BID-48049 IBM Tivoli Management Framework 'opts' Argument Stack Buffer Overflow Vulnerability Source: MISC Type: UNKNOWN http://zerodayinitiative.com/advisories/ZDI-11-169/ Source: XF Type: UNKNOWN tivoli-endpoint-lcfd-bo(67631) Source: XF Type: UNKNOWN tivoli-endpoint-lcfd-bo(67631) Source: CCN Type: IBM Support and Downloads CVE-2011-1220: IBM Tivoli Endpoint lcfd.exe opts Argument Remote Code Execution Source: CCN Type: IBM Web site IBM Tivoli Endpoint Source: EXPLOIT-DB Type: EXPLOIT Offensive Security Exploit Database [06-07-2011] Source: EXPLOIT-DB Type: EXPLOIT Offensive Security Exploit Database [06-11-2011] Source: CCN Type: ZDI-11-169 IBM Tivoli Endpoint lcfd.exe opts Argument Remote Code Execution Vulnerability | ||||||||
Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||
BACK |