CVE-2011-0975
Last modified
CVE-2011-0975 is a vulnerability of currently unknown severity. Stack-based buffer overflow in BMC PATROL Agent Service Daemon for in Performance Analysis for Servers, Performance Assurance for Servers, and Performance Assurance for Virtual Servers 7.4.00 through 7.5.10; Performance Analyzer and Performance Predictor for Servers 7.4.00 through 7.5.10; and Capacity Management Essentials 1.2.00 (7.4.15) allows remote attackers to execute arbitrary code via a crafted length value in a BGS_MULTIPLE_READS command to TCP port 6768.. EPSS estimates a 6.83% chance of exploitation in the next 30 days.
Description
Stack-based buffer overflow in BMC PATROL Agent Service Daemon for in Performance Analysis for Servers, Performance Assurance for Servers, and Performance Assurance for Virtual Servers 7.4.00 through 7.5.10; Performance Analyzer and Performance Predictor for Servers 7.4.00 through 7.5.10; and Capacity Management Essentials 1.2.00 (7.4.15) allows remote attackers to execute arbitrary code via a crafted length value in a BGS_MULTIPLE_READS command to TCP port 6768.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Bmc | Performance Analysis For Servers | 7.4.00 |
| Bmc | Performance Analysis For Servers | 7.4.10 |
| Bmc | Performance Analysis For Servers | 7.4.15 |
| Bmc | Performance Analysis For Servers | 7.5.00 |
| Bmc | Performance Analysis For Servers | 7.5.10 |
| Bmc | Performance Assurance For Servers | 7.4.00 |
| Bmc | Performance Assurance For Servers | 7.4.10 |
| Bmc | Performance Assurance For Servers | 7.4.15 |
| Bmc | Performance Assurance For Servers | 7.5.00 |
| Bmc | Performance Assurance For Servers | 7.5.10 |
| Bmc | Performance Assurance For Virtual Servers | 7.4.00 |
| Bmc | Performance Assurance For Virtual Servers | 7.4.10 |
| Bmc | Performance Assurance For Virtual Servers | 7.4.15 |
| Bmc | Performance Assurance For Virtual Servers | 7.5.00 |
| Bmc | Performance Assurance For Virtual Servers | 7.5.10 |
| Bmc | Performance Analyzer For Servers | 7.4.00 |
| Bmc | Performance Analyzer For Servers | 7.4.10 |
| Bmc | Performance Analyzer For Servers | 7.4.15 |
| Bmc | Performance Analyzer For Servers | 7.5.00 |
| Bmc | Performance Analyzer For Servers | 7.5.10 |
| Bmc | Performance Predictor For Servers | 7.4.00 |
| Bmc | Performance Predictor For Servers | 7.4.10 |
| Bmc | Performance Predictor For Servers | 7.4.15 |
| Bmc | Performance Predictor For Servers | 7.5.00 |
| Bmc | Performance Predictor For Servers | 7.5.10 |
| Bmc | Capacity Management Essentials | 1.2.00 |
References
- http://secunia.com/advisories/43177Vendor Advisory
- http://www.vupen.com/english/advisories/2011/0286Vendor Advisory
- http://secunia.com/advisories/43177Vendor Advisory
- http://www.vupen.com/english/advisories/2011/0286Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2011-0975?
How severe is CVE-2011-0975?
How do I fix CVE-2011-0975?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2011
- CVE-2011-0959Multiple cross-site scripting (XSS) vulnerabilities in Cisco…
- CVE-2011-0960Multiple SQL injection vulnerabilities in Cisco Unified Oper…
- CVE-2011-0961Cross-site scripting (XSS) vulnerability in cwhp/device.cent…
- CVE-2011-0962Cross-site scripting (XSS) vulnerability in CSCOnm/servlet/c…
- CVE-2011-0963The default configuration of the RADIUS authentication featu…
- CVE-2011-0966Directory traversal vulnerability in cwhp/auditLog.do in the…
- CVE-2011-0976Microsoft PowerPoint 2002 SP3, 2003 SP3, and 2007 SP2; Offic…
- CVE-2011-0977Use-after-free vulnerability in Microsoft Office XP SP3, Off…
- CVE-2011-0978Stack-based buffer overflow in Microsoft Excel 2002 SP3, 200…
- CVE-2011-0979Microsoft Excel 2002 SP3, 2003 SP3, 2007 SP2, and 2010; Offi…
- CVE-2011-0980Microsoft Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 …
- CVE-2011-0981Google Chrome before 9.0.597.94 does not properly perform ev…
Are you affected by CVE-2011-0975?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
