iDefense Security Advisory 03.31.07 – Remote exploitation of a multiple vulnerabilities within IBM Corp.’s Tivoli Provisioning Manager for OS Deployment allows attackers to crash the service or potentially execute arbitrary code with SYSTEM privileges. These vulnerabilities specifically exist in the handling of multi part/form-data HTTP POST requests. Malformed requests can cause invalid memory accesses leading to denial of service, or in some cases heap corruption. iDefense has confirmed the existence of these vulnerabilities within version 5.1.0.116 of Tivoli Provisioning Manager for OS Deployment. Older versions are suspected to be vulnerable as well.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/55558/03.31.07-2.txt
Source: https://packetstormsecurity.com/files/55558/iDEFENSE-Security-Advisory-2007-03-31.2.html

