• The Four Hundred
  • Subscribe
  • Media Kit
  • Contributors
  • About Us
  • Contact
Menu
  • The Four Hundred
  • Subscribe
  • Media Kit
  • Contributors
  • About Us
  • Contact
  • Another i5/OS-i Security Vulnerability Surfaces

    June 16, 2008 Timothy Prickett Morgan

    You have to work pretty hard to find a security vulnerability in the OS/400, i5/OS, and i operating systems, and according to a posting from computer security research and development company Secunia last week, to find the latest one, you have to look in a very unlikely place: the system modem.

    According to a Secunia advisory published last week, a security vulnerability in an operating system module with the name BrSmRcvAndCheck, which can apparently be exploited to cause a buffer overflow when running diagnostics on the modem port. Secunia rated this as a “less critical” patch when it issued its report on June 11 regarding the vulnerability, and said further that it would have an “unknown impact.” Which presumably means precisely what it says: That IBM has not been clear about the impact.

    The important thing, according to an IBM update on the matter is that the flaw has been patched. And in that report on the matter, IBM said that a task halt during IPL exploiting this vulnerability could cause a buffer overflow during the modem diagnostics, which in turn causes and error that then forces a main memory dump. IBM says that it has tweaked the microcode in the affected i5/OS and i platforms that are affected by this vulnerability, which includes i5/OS V5R4 and V5R4M5 and the new i 6.1. Get your PTFs handy.

    RELATED STORIES

    IBM Patches Security Flaw in Quickr for i5/OS

    Security Vulnerability Reported in i5/OS

    IBM Patches Security Flaw in OS/400 V5R3



                         Post this story to del.icio.us
                   Post this story to Digg
        Post this story to Slashdot

    Share this:

    • Reddit
    • Facebook
    • LinkedIn
    • Twitter
    • Email

    Tags: Tags: mtfh_rc, Volume 17, Number 24 -- June 16, 2008

    Sponsored by
    WorksRight Software

    Do you need area code information?
    Do you need ZIP Code information?
    Do you need ZIP+4 information?
    Do you need city name information?
    Do you need county information?
    Do you need a nearest dealer locator system?

    We can HELP! We have affordable AS/400 software and data to do all of the above. Whether you need a simple city name retrieval system or a sophisticated CASS postal coding system, we have it for you!

    The ZIP/CITY system is based on 5-digit ZIP Codes. You can retrieve city names, state names, county names, area codes, time zones, latitude, longitude, and more just by knowing the ZIP Code. We supply information on all the latest area code changes. A nearest dealer locator function is also included. ZIP/CITY includes software, data, monthly updates, and unlimited support. The cost is $495 per year.

    PER/ZIP4 is a sophisticated CASS certified postal coding system for assigning ZIP Codes, ZIP+4, carrier route, and delivery point codes. PER/ZIP4 also provides county names and FIPS codes. PER/ZIP4 can be used interactively, in batch, and with callable programs. PER/ZIP4 includes software, data, monthly updates, and unlimited support. The cost is $3,900 for the first year, and $1,950 for renewal.

    Just call us and we’ll arrange for 30 days FREE use of either ZIP/CITY or PER/ZIP4.

    WorksRight Software, Inc.
    Phone: 601-856-8337
    Fax: 601-856-9432
    Email: software@worksright.com
    Website: www.worksright.com

    Share this:

    • Reddit
    • Facebook
    • LinkedIn
    • Twitter
    • Email

    Admin Alert: All About the System i Attention Light Sysload Delivers Fine-Grain Monitoring for Virtual Servers

    Leave a Reply Cancel reply

TFH Volume: 17 Issue: 24

This Issue Sponsored By

    Table of Contents

    • Happy 20th Birthday, AS/400!
    • The Power 595 Takes the Top TPC-C Benchmark Ranking
    • The World Can’t Get Enough Disk Array Capacity
    • Mad Dog 21/21: iPhone Home
    • IBM Is Enjoying the Role of Green Giant
    • Reader Feedback on Forget About Platforms, Let’s Talk About Jobs
    • Another i5/OS-i Security Vulnerability Surfaces
    • There’s Still Money in Operating Systems, But Disruptions Loom
    • SPEC Members Start on Energy Benchmark for Web Servers
    • Enterprises Are Judged by the Measure of IT Performance

    Content archive

    • The Four Hundred
    • Four Hundred Stuff
    • Four Hundred Guru

    Recent Posts

    • Public Preview For Watson Code Assistant for i Available Soon
    • COMMON Youth Movement Continues at POWERUp 2025
    • IBM Preserves Memory Investments Across Power10 And Power11
    • Eradani Uses AI For New EDI And API Service
    • Picking Apart IBM’s $150 Billion In US Manufacturing And R&D
    • FAX/400 And CICS For i Are Dead. What Will IBM Kill Next?
    • Fresche Overhauls X-Analysis With Web UI, AI Smarts
    • Is It Time To Add The Rust Programming Language To IBM i?
    • Is IBM Going To Raise Prices On Power10 Expert Care?
    • IBM i PTF Guide, Volume 27, Number 20

    Subscribe

    To get news from IT Jungle sent to your inbox every week, subscribe to our newsletter.

    Pages

    • About Us
    • Contact
    • Contributors
    • Four Hundred Monitor
    • IBM i PTF Guide
    • Media Kit
    • Subscribe

    Search

    Copyright © 2025 IT Jungle