CVE-2011-1208
Last modified
CVE-2011-1208 is a vulnerability of currently unknown severity. IBM solidDB 4.5.x before 4.5.182, 6.0.x before 6.0.1069, 6.1.x and 6.3.x before 6.3 FP8 (aka 6.3.49), and 6.5.x before 6.5 FP4 (aka 6.5.0.4) does not properly handle the (1) rpc_test_svc_readwrite and (2) rpc_test_svc_done commands, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted command.. EPSS estimates a 3.26% chance of exploitation in the next 30 days.
Description
IBM solidDB 4.5.x before 4.5.182, 6.0.x before 6.0.1069, 6.1.x and 6.3.x before 6.3 FP8 (aka 6.3.49), and 6.5.x before 6.5 FP4 (aka 6.5.0.4) does not properly handle the (1) rpc_test_svc_readwrite and (2) rpc_test_svc_done commands, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted command.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Soliddb | 4.5.167 |
| Ibm | Soliddb | 4.5.168 |
| Ibm | Soliddb | 4.5.169 |
| Ibm | Soliddb | 4.5.173 |
| Ibm | Soliddb | 4.5.175 |
| Ibm | Soliddb | 4.5.176 |
| Ibm | Soliddb | 4.5.178 |
| Ibm | Soliddb | 4.5.179 |
| Ibm | Soliddb | 4.5.180 |
| Ibm | Soliddb | 4.5.181 |
| Ibm | Soliddb | 6.0.1060 |
| Ibm | Soliddb | 6.0.1061 |
| Ibm | Soliddb | 6.0.1064 |
| Ibm | Soliddb | 6.0.1065 |
| Ibm | Soliddb | 6.0.1066 |
| Ibm | Soliddb | 6.0.1067 |
| Ibm | Soliddb | 6.0.1068 |
| Ibm | Soliddb | 6.1.18 |
| Ibm | Soliddb | 6.1.20 |
| Ibm | Soliddb | 6.3.33 |
| Ibm | Soliddb | 6.3.37 |
| Ibm | Soliddb | 6.3.38 |
| Ibm | Soliddb | 6.3.39 |
| Ibm | Soliddb | 6.3.40 |
| Ibm | Soliddb | 6.3.44 |
| Ibm | Soliddb | 6.3.47 |
| Ibm | Soliddb | 6.3.48 |
| Ibm | Soliddb | 6.5.0.0 |
| Ibm | Soliddb | 6.5.0.1 |
| Ibm | Soliddb | 6.5.0.2 |
| Ibm | Soliddb | 6.5.0.3 |
References
- http://secunia.com/advisories/44380Vendor Advisory
- http://www.vupen.com/english/advisories/2011/1117Vendor Advisory
- http://secunia.com/advisories/44380Vendor Advisory
- http://www.vupen.com/english/advisories/2011/1117Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2011-1208?
How severe is CVE-2011-1208?
How do I fix CVE-2011-1208?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2011
- CVE-2011-1202The xsltGenerateIdFunction function in functions.c in libxsl…
- CVE-2011-1203Google Chrome before 10.0.648.127 does not properly handle S…
- CVE-2011-1204Google Chrome before 10.0.648.127 does not properly handle a…
- CVE-2011-1205Multiple buffer overflows in unspecified COM objects in Rati…
- CVE-2011-1206Stack-based buffer overflow in the server process in ibmslap…
- CVE-2011-1207The ActiveBar1 ActiveX control in the Data Dynamics ActiveBa…
- CVE-2011-1209IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.39 a…
- CVE-2011-1213Integer underflow in lzhsr.dll in Autonomy KeyView, as used …
- CVE-2011-1214Stack-based buffer overflow in rtfsr.dll in Autonomy KeyView…
- CVE-2011-1215Stack-based buffer overflow in mw8sr.dll in Autonomy KeyView…
- CVE-2011-1216Stack-based buffer overflow in assr.dll in Autonomy KeyView,…
- CVE-2011-1217Buffer overflow in kpprzrdr.dll in Autonomy KeyView, as used…
Are you affected by CVE-2011-1208?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
