CVE-2008-5982
Summary
| CVE | CVE-2008-5982 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2009-01-27 22:30:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Format string vulnerability in BMC PATROL Agent before 3.7.30 allows remote attackers to execute arbitrary code via format string specifiers in an invalid version number to TCP port 3181, which are not properly handled when writing a log message. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Bmc | Patrol Agent | 3.2 | All | All | All |
| Application | Bmc | Patrol Agent | 3.2.3 | All | All | All |
| Application | Bmc | Patrol Agent | 3.2.5 | All | All | All |
| Application | Bmc | Patrol Agent | 3.2.7 | All | All | All |
| Application | Bmc | Patrol Agent | 3.3.00 | All | All | All |
| Application | Bmc | Patrol Agent | 3.3.00 | All | nt | All |
| Application | Bmc | Patrol Agent | 3.3.00 | All | unix | All |
| Application | Bmc | Patrol Agent | 3.4.00 | All | All | All |
| Application | Bmc | Patrol Agent | 3.4.00 | All | nt | All |
| Application | Bmc | Patrol Agent | 3.4.00 | All | unix | All |
| Application | Bmc | Patrol Agent | 3.4.11 | All | All | All |
| Application | Bmc | Patrol Agent | 3.4.11 | All | nt | All |
| Application | Bmc | Patrol Agent | 3.4.11 | All | unix | All |
| Application | Bmc | Patrol Agent | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| BMC Patrol Agent Remote Format String Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| Zero Day Initiative | af854a3a-2127-422b-91ae-364da2661108 | www.zerodayinitiative.com | |
| Security Advisory SA33049 - BMC PATROL Version Logging Format String Vulnerability - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| BMC PATROL Agent Format String Bug Lets Remote Users Execute Arbitrary Code - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.