tfh
Volume 17, Number 24 -- June 16, 2008

Another i5/OS-i Security Vulnerability Surfaces

Published: June 16, 2008

by Timothy Prickett Morgan

You have to work pretty hard to find a security vulnerability in the OS/400, i5/OS, and i operating systems, and according to a posting from computer security research and development company Secunia last week, to find the latest one, you have to look in a very unlikely place: the system modem.

According to a Secunia advisory published last week, a security vulnerability in an operating system module with the name BrSmRcvAndCheck, which can apparently be exploited to cause a buffer overflow when running diagnostics on the modem port. Secunia rated this as a "less critical" patch when it issued its report on June 11 regarding the vulnerability, and said further that it would have an "unknown impact." Which presumably means precisely what it says: That IBM has not been clear about the impact.

The important thing, according to an IBM update on the matter is that the flaw has been patched. And in that report on the matter, IBM said that a task halt during IPL exploiting this vulnerability could cause a buffer overflow during the modem diagnostics, which in turn causes and error that then forces a main memory dump. IBM says that it has tweaked the microcode in the affected i5/OS and i platforms that are affected by this vulnerability, which includes i5/OS V5R4 and V5R4M5 and the new i 6.1. Get your PTFs handy.


RELATED STORIES

IBM Patches Security Flaw in Quickr for i5/OS

Security Vulnerability Reported in i5/OS

IBM Patches Security Flaw in OS/400 V5R3



                     Post this story to del.icio.us
               Post this story to Digg
    Post this story to Slashdot


Sponsored By
ALDON

Compliance got you seeing red?

Keep your organization in line with
Aldon's Application Lifecycle Management solutions.

Whether you fall under HIPAA, Sarbanes-Oxley,
ITIL, Basel II or other initiatives, Aldon ALM will
simplify your life and ensure regulatory compliance.

Download our White Paper, and learn how Aldon can bring you
the best practices you need to achieve governance.

Click here to download


Editor: Timothy Prickett Morgan
Contributing Editors: Dan Burger, Joe Hertvik, Brian Kelly, Shannon O'Donnell,
Mary Lou Roberts, Victor Rozek, Kevin Vandever, Hesh Wiener, Alex Woodie
Publisher and Advertising Director: Jenny Thomas
Advertising Sales Representative: Kim Reed
Contact the Editors: To contact anyone on the IT Jungle Team
Go to our contacts page and send us a message.

Sponsored Links

OCEAN:  Technical conference, June 30, 2008, Irvine, CA
RJS Software Systems:  Spring Sale! Savings on WebDocs and Value Bundles
COMMON:  Join us at the Focus 2008 workshop conference, October 5 - 8, in San Francisco, California

 

 

IT Jungle Store Top Book Picks

Easy Steps to Internet Programming for AS/400, iSeries, and System i: List Price, $49.95
Getting Started with PHP for i5/OS: List Price, $59.95
The System i RPG & RPG IV Tutorial and Lab Exercises: List Price, $59.95
The System i Pocket RPG & RPG IV Guide: List Price, $69.95
The iSeries Pocket Database Guide: List Price, $59.00
The iSeries Pocket Developers' Guide: List Price, $59.00
The iSeries Pocket SQL Guide: List Price, $59.00
The iSeries Pocket Query Guide: List Price, $49.00
The iSeries Pocket WebFacing Primer: List Price, $39.00
Migrating to WebSphere Express for iSeries: List Price, $49.00
iSeries Express Web Implementer's Guide: List Price, $59.00
Getting Started with WebSphere Development Studio for iSeries: List Price, $79.95
Getting Started With WebSphere Development Studio Client for iSeries: List Price, $89.00
Getting Started with WebSphere Express for iSeries: List Price, $49.00
WebFacing Application Design and Development Guide: List Price, $55.00
Can the AS/400 Survive IBM?: List Price, $49.00
The All-Everything Machine: List Price, $29.95
Chip Wars: List Price, $29.95


 
The Linux Beacon
How's Red Hat Enterprise Linux 5 Doing?

AMD Finishes Off Quad Cores with Budapest Opterons

Forget About Platforms, Let's Talk About Jobs

As I See It: Citizen CEO

Looks Like Unisys Is Reselling Sun's X4600 Opteron Boxes

Four Hundred Stuff
Bank's Approach to Biometric Authentication a 'Valid' One

Programmer Conveniences Added to BCD's WebSmart ILE

ASNA Brings RPG to .NET Migration Software to Latest Windows IDE

Safestone Re-emerges with New Corporate Identity, i OS Security Tools

NetManage and HiT Software Partner for Structured Data

Big Iron
The Back and Forth of the PSI-IBM Lawsuit

Top Mainframe Stories From Around the Web

Chats, Webinars, Seminars, Shows, and Other Happenings

Four Hundred Guru
Keeping 5250 Alive

Seeking Advice on REXX

Admin Alert: All About the System i Attention Light

System i PTF Guide
June 7, 2008: Volume 10, Number 23

May 31, 2008: Volume 10, Number 22

May 24, 2008: Volume 10, Number 21

May 17, 2008: Volume 10, Number 20

May 10, 2008: Volume 10, Number 19

May 3, 2008: Volume 10, Number 18

The Windows Observer
Muglia Leads Off Week Two of Tech Ed

Fixes for Critical Security Flaws Issued by Microsoft

New Windows Clustering Capability Has HA Partners Shifting Gears

Stratus Builds Its First HA Clustering Product Atop Xen

Icahn Pushes Micro-Hoo in a Series of Letters

The Unix Guardian
The Power 595 Takes the Top TPC-C Benchmark Ranking

AMD Offers Clock Cranks on Barcelona Opterons

Forget About Platforms, Let's Talk About Jobs

As I See It: Citizen CEO

IBM Is Enjoying the Role of Green Giant

Four Hundred Monitor
Four Hundred Monitor's
Full iSeries Events Calendar

THIS ISSUE SPONSORED BY:

looksoftware
Aldon
BCD
Vision Solutions
COMMON


Printer Friendly Version


TABLE OF CONTENTS
Happy 20th Birthday, AS/400!

The Power 595 Takes the Top TPC-C Benchmark Ranking

The World Can't Get Enough Disk Array Capacity

Mad Dog 21/21: iPhone Home

IBM Is Enjoying the Role of Green Giant

But Wait, There's More:

Reader Feedback on Forget About Platforms, Let's Talk About Jobs . . . Another i5/OS-i Security Vulnerability Surfaces . . . There's Still Money in Operating Systems, But Disruptions Loom . . . SPEC Members Start on Energy Benchmark for Web Servers . . . Enterprises Are Judged by the Measure of IT Performance . . .

The Four Hundred

BACK ISSUES





 
Subscription Information:
You can unsubscribe, change your email address, or sign up for any of IT Jungle's free e-newsletters through our Web site at http://www.itjungle.com/sub/subscribe.html.

Copyright © 1996-2008 Guild Companies, Inc. All Rights Reserved.
Guild Companies, Inc., 50 Park Terrace East, Suite 8F, New York, NY 10034

Privacy Statement