Vulnerabilities > CVE-2011-1385 - Resource Management Errors vulnerability in IBM AIX and Vios

047910
CVSS 7.8 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
COMPLETE
network
low complexity
ibm
CWE-399
nessus

Summary

IBM AIX 5.3, 6.1, and 7.1, and VIOS 2.1.x and 2.2.x, allows remote attackers to cause a denial of service (system crash) via an ICMP Echo Reply packet that contains 1 in the Identifier field, a different vulnerability than CVE-2012-0194.

Common Weakness Enumeration (CWE)

Nessus

  • NASL familyAIX Local Security Checks
    NASL idAIX_U849141.NASL
    descriptionThe remote host is missing AIX PTF U849141, which is related to the security of the package bos.net.tcp.client.
    last seen2020-06-01
    modified2020-06-02
    plugin id59075
    published2012-05-11
    reporterThis script is Copyright (C) 2012-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/59075
    titleAIX 6.1 TL 6 : bos.net.tcp.client (U849141)
  • NASL familyAIX Local Security Checks
    NASL idAIX_U842598.NASL
    descriptionThe remote host is missing AIX PTF U842598, which is related to the security of the package bos.net.tcp.client.
    last seen2020-06-01
    modified2020-06-02
    plugin id59073
    published2012-05-11
    reporterThis script is Copyright (C) 2012-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/59073
    titleAIX 6.1 TL 5 : bos.net.tcp.client (U842598)
  • NASL familyAIX Local Security Checks
    NASL idAIX_U846526.NASL
    descriptionThe remote host is missing AIX PTF U846526, which is related to the security of the package bos.net.tcp.client.
    last seen2020-06-01
    modified2020-06-02
    plugin id59074
    published2012-05-11
    reporterThis script is Copyright (C) 2012-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/59074
    titleAIX 7.1 : bos.net.tcp.client (U846526)
  • NASL familyAIX Local Security Checks
    NASL idAIX_IV13827.NASL
    descriptionThere is an error in the handling of a particular ICMP packet in which a remote user can cause a denial of service. Note: The ifixes provided also contain the fix for CVE-2012-0194 since they affect the same fileset. See the following for CVE-2012-0194: http://aix.software.ibm.com/aix/efixes/security/large_send_a dvisory.asc.
    last seen2017-10-29
    modified2014-03-11
    plugin id63708
    published2013-01-24
    reporterTenable
    sourcehttps://www.tenable.com/plugins/index.php?view=single&id=63708
    titleAIX 5.3 TL 12 : icmp (IV13827)
  • NASL familyAIX Local Security Checks
    NASL idAIX_IV13820.NASL
    descriptionThere is an error in the handling of a particular ICMP packet in which a remote user can cause a denial of service. Note: The ifixes provided also contain the fix for CVE-2012-0194 since they affect the same fileset. See the following for CVE-2012-0194: http://aix.software.ibm.com/aix/efixes/security/large_send_a dvisory.asc.
    last seen2017-10-29
    modified2014-03-11
    plugin id64301
    published2013-01-30
    reporterTenable
    sourcehttps://www.tenable.com/plugins/index.php?view=single&id=64301
    titleAIX 6.1 TL 6 : icmp (IV13820)
  • NASL familyAIX Local Security Checks
    NASL idAIX_U846741.NASL
    descriptionThe remote host is missing AIX PTF U846741, which is related to the security of the package bos.net.tcp.client.
    last seen2020-06-01
    modified2020-06-02
    plugin id72843
    published2014-03-06
    reporterThis script is Copyright (C) 2014-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/72843
    titleAIX 7.1 TL 1 : bos.net.tcp.client (U846741)
  • NASL familyAIX Local Security Checks
    NASL idAIX_IV13751.NASL
    descriptionThere is an error in the handling of a particular ICMP packet in which a remote user can cause a denial of service. Note: The ifixes provided also contain the fix for CVE-2012-0194 since they affect the same fileset. See the following for CVE-2012-0194: http://aix.software.ibm.com/aix/efixes/security/large_send_a dvisory.asc.
    last seen2017-10-29
    modified2014-03-11
    plugin id64300
    published2013-01-30
    reporterTenable
    sourcehttps://www.tenable.com/plugins/index.php?view=single&id=64300
    titleAIX 6.1 TL 5 : icmp (IV13751)
  • NASL familyAIX Local Security Checks
    NASL idAIX_U846071.NASL
    descriptionThe remote host is missing AIX PTF U846071, which is related to the security of the package bos.net.tcp.client.
    last seen2020-06-01
    modified2020-06-02
    plugin id72841
    published2014-03-06
    reporterThis script is Copyright (C) 2014-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/72841
    titleAIX 6.1 TL 7 : bos.net.tcp.client (U846071)
  • NASL familyAIX Local Security Checks
    NASL idAIX_IV14210.NASL
    descriptionThere is an error in the handling of a particular ICMP packet in which a remote user can cause a denial of service. Note: The ifixes provided also contain the fix for CVE-2012-0194 since they affect the same fileset. See the following for CVE-2012-0194: http://aix.software.ibm.com/aix/efixes/security/large_send_a dvisory.asc.
    last seen2017-10-29
    modified2014-03-11
    plugin id64303
    published2013-01-30
    reporterTenable
    sourcehttps://www.tenable.com/plugins/index.php?view=single&id=64303
    titleAIX 7.1 TL 0 : icmp (IV14210)
  • NASL familyAIX Local Security Checks
    NASL idAIX_U846347.NASL
    descriptionThe remote host is missing AIX PTF U846347, which is related to the security of the package bos.net.tcp.client. Vulnerability which allows remote attackers to (1) register or (2) unregister RPC services, and consequently cause a denial of service or obtain sensitive information from interprocess communication, via crafted UDP packets containing service commands. Note: The ifix provided also contains the fix for CVE-2012-0194 and CVE-2011-1385 since they affect the same fileset. See the following for CVE-2012-0194: http://aix.software.ibm.com/aix/efixes/security/large_send_a dvisory.asc CVE-2011-1385: http://aix.software.ibm.com/aix/efixes/security/icmp_advisor y.asc.
    last seen2020-06-01
    modified2020-06-02
    plugin id72842
    published2014-03-06
    reporterThis script is Copyright (C) 2014-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/72842
    titleAIX 5.3 TL 12 : bos.net.tcp.client (U846347)
  • NASL familyAIX Local Security Checks
    NASL idAIX_U841068.NASL
    descriptionThe remote host is missing AIX PTF U841068, which is related to the security of the package bos.net.tcp.client. AIX could allow a remote attacker to cause a denial of service, caused by an error when the TCP large send offload option is enabled on a network interface. By sending a specially crafted sequence of packets, an attacker could exploit this vulnerability to cause a kernel panic.
    last seen2020-06-01
    modified2020-06-02
    plugin id72839
    published2014-03-06
    reporterThis script is Copyright (C) 2014-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/72839
    titleAIX 6.1 TL 7 : bos.net.tcp.client (U841068)
  • NASL familyAIX Local Security Checks
    NASL idAIX_U843468.NASL
    descriptionThe remote host is missing AIX PTF U843468, which is related to the security of the package bos.net.tcp.client. AIX could allow a remote attacker to cause a denial of service, caused by an error when the TCP large send offload option is enabled on a network interface. By sending a specially crafted sequence of packets, an attacker could exploit this vulnerability to cause a kernel panic.
    last seen2020-06-01
    modified2020-06-02
    plugin id72840
    published2014-03-06
    reporterThis script is Copyright (C) 2014-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/72840
    titleAIX 7.1 TL 1 : bos.net.tcp.client (U843468)