Skip the navigation

IBM preps patches for security flaw

Tivoli Directory Server 6.x hole could leave software exposed

By Denise Dubie
February 17, 2006 12:00 PM ET

Network World - IBM said it is working on developing and distributing fixes to a vulnerability detected in IBM Tivoli Directory Server 6.x that could leave the software exposed to denial-of-service attacks.
According to IBM, Tivoli Directory Server 6.x provides an LDAP identity infrastructure that can serve as the foundation for deploying identity management applications and Web services. The flaw, detected earlier this week, was deemed less critical by Secunia Research, which reported the vulnerability in a security advisory. The vulnerability has been discovered in Version 6 of the software and the Web site indicates other versions could be affected.
According to the Secunia security advisory, the vulnerability is caused due to an error within the LDAP server when handling certain requests, and "this can be exploited to crash the server via specially-crafted request sent to port 389/tcp." The error can cause the server to crash due to a denial-of-service attack committed on the local network, but security experts say the threat is minimal considering the nature of the flaw.
"This flaw is not as critical as some because it can only be exploited on the local network and even if it is compromised, the error would only be able to crash the server, not expose the data or put information at risk," says Steve Manzuik, security product manager with eEye Research. "Basically, someone on the local network could crash the machine running the software. It doesn't allow for any kind of actual access to the machine or to the data."
The Secunia Web site suggests until IBM readies patches that Tivoli Directory Server administrators restrict access to the LDAP service in the software and on the server. Because the flaw can only be exploited on the local network, Manzuik says the threat becomes even less critical, but still should be addressed.
"It's definitely something you should patch, but not something to patch out of your normal patch process," he explains. "IBM is fairly responsive to flaws. Patching this for customers just depends on how quickly IBM can get the patch out."
Big Blue, which last year addressed a similar flaw with the directory software, reported it is working to develop and deliver fixes to the problem across the platforms it affects throughout February.
A company spokeswoman says while IBM is still working to discover all customers impacted, the flaw does not impact AIX platforms. And while the spokeswoman says the directory server software isn't one of the more popular IBM products, the company is expected next week to release more information onthe specific fixes for various platforms and address the issue in letters to customers.

Reprinted with permission from NetworkWorld.com. Story copyright 2010 Network World, Inc. All rights reserved.
Additional Resources
Forrester Consulting - Optimizing Users and Applications in a Mobile World
WHITE PAPER
Solving application issues over the WAN requires careful consideration. Based on their independent research, Forrester Consulting offers recommendations on how to tackle application performance issues, insufficient bandwidth and the inability to quickly restore users in a disaster.

Read now.

Security KnowledgeVault
WHITE PAPER
Security is not an option. This KnowledgeVault Series offers professional advice how to be proactive in the fight against cybercrimes and multi-layered security threats; how to adopt a holistic approach to protecting and managing data; and how to hire a qualified security assessor. Make security your Number 1 priority.

Read now.

Cut Communications Costs Once and for All
WHITE PAPER
New IP-based communications systems are being deployed by small and midsized businesses at a rapid rate. Learn how these organizations are enabling faster responsiveness, creating better customer experiences, speeding office or mobile interactions, and dramatically reducing existing communications costs.

Read now.

Malware and Vulnerabilities White Papers
Reducing the Cost and Complexity of Web Vulnerability Management
Hackers and cybercriminals are constantly refining their attacks and targets; which means you need agile tools to stay ahead of them.

Download this...
Overcome Top 7 Admin Challenges of Active Directory
As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
Insiders Can Ruin Your Company. Take Action.
Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
Top Solutions and Tools to Prevent Devastating Malware
Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring...
Streamline Compliance and Increase ROI
Streamline, simplify, and automate compliance related activities; especially those that impact multiple business units. This white paper from NetIQ, outlines solutions that will...
All Malware and Vulnerabilities White Papers
Malware and Vulnerabilities Webcasts
Optimizing Networks for the Cloud
Join guest speaker, Rohit Mehra, IDC Director of Enterprise Communications Infrastructure, to explore current trends, discuss best practices for optimizing Data Center and...
Apps QuickStart Series Part 2: Designing and Deploying SQL Server on VMware vSphere
Download this webcast to learn about the design considerations for virtualizing SQL workloads, performance and scalability information and high-availability options, as well as...
Apps QuickStart Series Part 1: Designing and Deploying Exchange 2010 on VMware vSphere
Download this webcast to learn the virtual hardware design considerations for Exchange 2010, deployment using the building block approach, options for high-availability and...
Customer Spotlight: How IPC The Hospitalist Company Implemented Oracle on VMware
Have you been looking to hear about customer's experiences with the new VMware vCenter Site Recovery Manager product? View this webcast to learn...
Virtualize Business-Critical Applications with Confidence
Virtualizing business-critical applications has become a key focus for organizations as they move along their virtualization journey. With the launch of VMware vSphere®...
All Malware and Vulnerabilities Webcasts
Newsletter Sign-Up

Receive the latest news test, reviews and trends on your favorite technology topics

Choose a newsletter
  1. View all newsletters | Privacy Policy
IT Jobs