Vulnerabilities > CVE-2007-1868 - Stack Buffer Overflow vulnerability in IBM Tivoli Provisioning Manager OS Deployment 5.1.0.116

047910
CVSS 10.0 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
low complexity
ibm
critical
nessus
exploit available
metasploit

Summary

The management service in IBM Tivoli Provisioning Manager for OS Deployment before 5.1 Fix Pack 2 does not properly handle multipart/form-data in HTTP POST requests, which allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via crafted POST requests to port 8080/tcp or 443/tcp.

Vulnerable Configurations

Part Description Count
Application
Ibm
1

Exploit-Db

descriptionIBM TPM for OS Deployment 5.1.0.x rembo.exe Buffer Overflow. CVE-2007-1868. Remote exploit for windows platform
idEDB-ID:16810
last seen2016-02-02
modified2010-09-20
published2010-09-20
reportermetasploit
sourcehttps://www.exploit-db.com/download/16810/
titleIBM TPM for OS Deployment 5.1.0.x rembo.exe Buffer Overflow

Metasploit

descriptionThis is a stack buffer overflow exploit for IBM Tivoli Provisioning Manager for OS Deployment version 5.1.0.X.
idMSF:EXPLOIT/WINDOWS/HTTP/IBM_TPMFOSD_OVERFLOW
last seen2020-05-23
modified2017-07-24
published2007-05-03
references
reporterRapid7
sourcehttps://github.com/rapid7/metasploit-framework/blob/master//modules/exploits/windows/http/ibm_tpmfosd_overflow.rb
titleIBM TPM for OS Deployment 5.1.0.x rembo.exe Buffer Overflow

Nessus

  • NASL familyWeb Servers
    NASL idIBM_TPMFOSD_CORRUPTION.NASL
    descriptionThe remote host is running IBM Tivoli Provisioning Manager for OS Deployment. The version of this software contains multiple unspecified memory corruption vulnerabilities in the HTTP server. A remote attacker may exploit these flaws to crash the service or execute code on the remote host with the privileges of the TPM server.
    last seen2020-06-01
    modified2020-06-02
    plugin id25005
    published2007-04-07
    reporterThis script is Copyright (C) 2007-2018 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/25005
    titleIBM Tivoli Provisioning Manager OS Deployment Multiple Unspecified Input Validation Vulnerabilities
  • NASL familyWeb Servers
    NASL idIBM_TPMFOSD_OVERFLOW.NASL
    descriptionThe remote host is running IBM Tivoli Provisioning Manager for OS Deployment. The version of this software has multiple buffer overflow vulnerabilities in the HTTP server. A remote attacker may exploit these flaws to crash the service or execute code on the remote host with the privileges of the TPM server.
    last seen2020-06-01
    modified2020-06-02
    plugin id25149
    published2007-05-03
    reporterThis script is Copyright (C) 2007-2018 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/25149
    titleIBM Tivoli Provisioning Manager OS Deployment Multiple Stack Overflows

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/83093/ibm_tpmfosd_overflow.rb.txt
idPACKETSTORM:83093
last seen2016-12-05
published2009-11-26
reportertoto
sourcehttps://packetstormsecurity.com/files/83093/IBM-TPM-for-OS-Deployment-5.1.0.x-rembo.exe-Buffer-Overflow.html
titleIBM TPM for OS Deployment 5.1.0.x rembo.exe Buffer Overflow