Infesting you with Virus News
 

News

Contributed by: Lauren Gerber
Date: June 22, 2009
Lauren Gerber
-3
Vote
0

Run From The IBM AIX Buffer Overflow Vulnerability

 

Ladies and gentlemen I welcome you to yet another fun and exciting, reading experience with regards to a vulnerability. What it is this time you may be wondering? Good question, this time I shall be sharing some information with regards to an IBM AIX Buffer Overflow Vulnerability. This vulnerability was discovered in IBM AIX, in the ToolTalk library.Buffer_overflow.png

This specific and dangerous vulnerability enables malicious individuals to execute arbitrary code. A remote user is able to execute arbitrary code on a targeted system. One of the of the client servers developed by IMB includes the IBM Lotus Notes. Some of the files with regard to IBM Lotus Notes may include but are not limited to the following: f10494_ntmulti.exe, f4700_nnotesmm.exe, f7076_nlnotes.exe, f7387_ntaskldr.exe, nsl.exe as well as nsl.exe1.

A remote user is able to send tampered with data to the rpc.ttdbserver. This will directly result in a buffer overflow, in the ToolTalk library (libtt.a), being triggered. A key aspect to take into consideration is that this code will unfortunately, run with root privileges.

The vulnerability can be found in the following locations:

  • /usr/dt/lib/libtt.a
  • /usr/dt/bin/rpc.ttdbserver

How do you know if your system is vulnerable?
If you would like to determine if your system is vulnerable you will need to accurately execute the following command: lslpp -L X11.Dt.ToolTalk 

The solution to this is to apply the available fixes and updates. It can thus be quoted in conclusion: "If computers get too powerful, we can organize them into a committee - that will do them in". - Bradley's Bromide

User Comments

iyotaka June 23, 2009
lslpp -L X11/Dt.Tooltalk - and what software level is potentially a threat, which is fixed?

*.exe - are those windows(-like) executables?

Too little info to be useful.
Name:
Email:
Website:
Comment:
Please type 5-digit security code below:
Captcha image for spam protection

Software Downloads

Free Spyhunter Scanner (Spyware/Trojan Detection). DETECT Spyware, Trojans, Worms, Viruses and malware on your PC absolutely FREE.
Award Winning software, Fixes registry and improves computer performance. Created by a division of Symantec, this tool will scan your registry and find errors that can be later cleaned either individually or all together.
The tool is used to prevent the installation of spyware and other potentially unwanted software. As soon as you download it, you will be able to protect your system.

Latest Comments

March 15, 2010
It is time for windows board to wake up and lock all system files , only to be opend by getting a licence... more..
March 15, 2010
Help us! Still cannot get Antivirus to update or connect to via browser or ping symantec, avg, mcafee,... more..
March 15, 2010
I'd like to say hi im new here i've been lurking around for the past few weeks and finally decided to... more..
more comments..
rss
Home > Computer Security > Run From The IBM AIX Buffer Overflow Vulnerability