CVE-2011-1206 - CVE House
Back to Database
Status published Critical CVE-2011-1206

Stack-based buffer overflow in the server process in ibmslapd.exe in...

Vulnerability Description

Stack-based buffer overflow in the server process in ibmslapd.exe in IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-IF0010, 6.0 before 6.0.0.67 (aka 6.0.0.8-TIV-ITDS-IF0009), 6.1 before 6.1.0.40 (aka 6.1.0.5-TIV-ITDS-IF0003), 6.2 before 6.2.0.16 (aka 6.2.0.3-TIV-ITDS-IF0002), and 6.3 before 6.3.0.3 (aka 6.3.0.0-TIV-ITDS-IF0003) allows remote attackers to execute arbitrary code via a crafted LDAP request. NOTE: some of these details are obtained from third party information.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2011-1206

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

tivoli directory server
Vulnerable Versions:
5.2.0, 5.2.0.4, 6.0, 6.0.0.0, 6.0.0.1, 6.0.0.7, 6.0.0.8, 6.0.0.14, 6.0.0.19, 6.0.0.33, 6.0.0.41, 6.0.0.45, 6.0.0.52, 6.0.0.53, 6.0.0.54, 6.0.0.55, 6.0.0.56, 6.0.0.57, 6.0.0.58, 6.0.0.59, 6.0.0.60, 6.0.0.61, 6.0.0.62, 6.0.0.63, 6.0.0.64, 6.0.0.65, 6.0.0.66, 6.1.0.0, 6.1.0.1, 6.1.0.2, 6.1.0.3, 6.1.0.4, 6.1.0.5, 6.1.0.6, 6.1.0.7, 6.1.0.8, 6.1.0.9, 6.1.0.10, 6.1.0.11, 6.1.0.12, 6.1.0.13, 6.1.0.14, 6.1.0.15, 6.1.0.17, 6.1.0.18, 6.1.0.19, 6.1.0.20, 6.1.0.21, 6.1.0.22, 6.1.0.23, 6.1.0.24, 6.1.0.25, 6.1.0.26, 6.1.0.27, 6.1.0.28, 6.1.0.29, 6.1.0.30, 6.1.0.31, 6.1.0.32, 6.1.0.33, 6.1.0.34, 6.1.0.35, 6.1.0.36, 6.1.0.37, 6.1.0.38, 6.1.0.39, 6.2.0.0, 6.2.0.1, 6.2.0.2, 6.2.0.3, 6.2.0.4, 6.2.0.5, 6.2.0.6, 6.2.0.7, 6.2.0.8, 6.2.0.10, 6.2.0.11, 6.2.0.12, 6.2.0.13, 6.2.0.14, 6.2.0.15, 6.3.0.0, 6.3.0.1, 6.3.0.2

Timeline

Official Publish: April 21st, 2011
Last Modified: August 6th, 2024
Added to House: July 19th, 2026

CVSS Vectors

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.