Lucene search

K
zdiTenable Network SecurityZDI-11-142
HistoryApr 26, 2011 - 12:00 a.m.

IBM solidDB solid.exe rpc_test_svc Commands Multiple DoS Vulnerabilities

2011-04-2600:00:00
Tenable Network Security
www.zerodayinitiative.com
10

EPSS

0.08

Percentile

94.3%

This vulnerability allows remote attackers to create a denial of service condition on vulnerable installations of IBM SolidDB. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the rpc_test_svc_readwrite and rpc_test_svc_done commands. By issuing these commands remotely to TCP port 2315, an attacker can cause the solidDB.exe process to dereference a NULL pointer and subsequently crash.

EPSS

0.08

Percentile

94.3%