Wednesday, July 18, 2007

[NT] IBM Tivoli Provisioning Manager for OS Deployment TFTP Blocksize DoS Vulnerability

The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion

The SecuriTeam alerts list - Free, Accurate, Independent.

Get your security news from a reliable source.
http://www.securiteam.com/mailinglist.html


- - - - - - - - -

IBM Tivoli Provisioning Manager for OS Deployment TFTP Blocksize DoS
Vulnerability
------------------------------------------------------------------------


SUMMARY

<http://www-306.ibm.com/software/tivoli/products/prov-mgr-os-deploy/ >
IBM Corp.'s Tivoli Provisioning Manager for OS Deployment is "a network
boot server that facilitates central management of networked workstations.
It implements Preboot Execution Environment (PXE), a Web-based
administration service, DHCP, TFTP, and several additional protocols".

Remote exploitation of a denial of service vulnerability within version
5.1.0.2 of IBM Corp.'s Tivoli Provisioning Manager for OS Deployment
allows attackers to deny service to all product functionality.

DETAILS

Vulnerable Systems:
* IBM Corp.'s Tivoli Provisioning Manager for OS Deployment version
5.1.0.2

Immune Systems:
* IBM Corp.'s Tivoli Provisioning Manager for OS Deployment version
5.1.0.116

This vulnerability specifically exists in the TFTP protocol
implementation. When processing a read request (RRQ), an integer division
by zero error can be triggered by supplying an invalid "blksize" argument.
This exception is not handled and will result in the rembo.exe service
terminating.

Exploitation allows an attacker to cause the service to terminate
unexpectedly due to an exception that occurs when dividing by zero.

No authentication is required to access the vulnerable code. The attacker
need only be able to send a specially crafted request to the TFTP port
(UDP port 69) of the vulnerable machine.

This will deny service to all functionality provided by this service. This
includes DHCP, TFTP, PXE, HTTP, HTTPS, as well as several other services.

Vendor Status:
The IBM Tivoli team has addressed this vulnerability within Tivoli
Provisioning Manager for OS Deployment 5.1 Fix Pack 3. More information is
available from IBM Document swg24016347 at the following URL.
<http://www-1.ibm.com/support/docview.wss?uid=swg24016347>

http://www-1.ibm.com/support/docview.wss?uid=swg24016347

Disclosure Timeline:
* 06/19/2007 - Initial vendor notification
* 06/19/2007 - Initial vendor response
* 07/17/2007 - Coordinated public disclosure


ADDITIONAL INFORMATION

The information has been provided by iDefense.
The original article can be found at:

<http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=560>

http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=560

========================================


This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com


====================
====================

DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.

13 comments:

  1. Anonymous1:52 PM

    diazepam no prescription needed molecular mass diazepam valium - diazepam rare side effects

    ReplyDelete
  2. Anonymous2:30 PM

    diazepam overdose diazepam contraindications - www.buy-diazepam-online.net

    ReplyDelete
  3. Anonymous3:20 PM

    alprazolam online can i take 2mg of xanax - xanax and employment drug test

    ReplyDelete
  4. Anonymous2:40 AM

    order ativan ativan side effects long - ativan side effects vision

    ReplyDelete
  5. Anonymous3:59 AM

    zolpidem ambien what is zolpidem 10 mg used for - zolpidem tartrate photos

    ReplyDelete
  6. Anonymous5:12 AM

    generic ambien buy ambien side effects hair loss - where to buy ambien online

    ReplyDelete
  7. Anonymous2:36 PM

    ativan mg died ativan overdose - ativan 57

    ReplyDelete
  8. Anonymous6:42 AM

    generic xanax xanax side effects paranoia - buy xanax with paypal

    ReplyDelete
  9. Anonymous2:16 AM

    buy diazepam buy diazepam tablets - diazepam dosage usa

    ReplyDelete
  10. Anonymous5:16 PM

    buy soma online carisoprodol - v 2410 side effects - soma medication mechanism action

    ReplyDelete
  11. Anonymous10:45 AM

    soma for sale soma medication description - carisoprodol from india

    ReplyDelete
  12. Anonymous1:49 PM

    valium purchase very cheap valium - valium half life 10 mg

    ReplyDelete
  13. Anonymous5:25 PM

    buy ambien online order ambien cr online - does ambien generic work

    ReplyDelete