{"api_version":"1","generated_at":"2026-07-24T21:42:29+00:00","cve":"CVE-2010-4604","urls":{"html":"https://cve.report/CVE-2010-4604","api":"https://cve.report/api/cve/CVE-2010-4604.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2010-4604","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2010-4604"},"summary":{"title":"CVE-2010-4604","description":"Stack-based buffer overflow in the GeneratePassword function in dsmtca (aka the Trusted Communications Agent or TCA) in the backup-archive client in IBM Tivoli Storage Manager (TSM) 5.3.x before 5.3.6.10, 5.4.x before 5.4.3.4, 5.5.x before 5.5.2.10, and 6.1.x before 6.1.3.1 on Unix and Linux allows local users to gain privileges by specifying a long LANG environment variable, and then sending a request over a pipe.","state":"PUBLISHED","assigner":"mitre","published_at":"2010-12-29 18:00:03","updated_at":"2026-04-29 01:13:23"},"problem_types":["CWE-787","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.2","severity":"","vector":"AV:L/AC:L/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:C/I:C/A:C","baseScore":7.2,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://www.securityfocus.com/archive/1/515263/100/0/threaded","name":"http://www.securityfocus.com/archive/1/515263/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory","VDB Entry"],"title":"SecurityFocus","mime":"text/x-c","httpstatus":"200","archivestatus":"200"},{"url":"http://www-01.ibm.com/support/docview.wss?uid=swg1IC65491","name":"http://www-01.ibm.com/support/docview.wss?uid=swg1IC65491","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"IBM Error - United States","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2010/3251","name":"http://www.vupen.com/english/advisories/2010/3251","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.ibm.com/support/docview.wss?uid=swg21454745","name":"http://www.ibm.com/support/docview.wss?uid=swg21454745","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"],"title":"IBM notice: The page you requested cannot be displayed","mime":"text/html","httpstatus":"404","archivestatus":"410"},{"url":"http://secunia.com/advisories/42639","name":"http://secunia.com/advisories/42639","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"],"title":"IBM Tivoli Storage Manager (TSM) Client Multiple Vulnerabilities - Advisories - Community","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securitytracker.com/id?1024901","name":"http://securitytracker.com/id?1024901","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory","VDB Entry"],"title":"SecurityTracker.com Archives - IBM Tivoli Storage Manager Lets Local Users Gain Elevated Privileges","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.kryptoslogic.com/advisories/2010/kryptoslogic-ibm-tivoli-dsmtca.txt","name":"http://www.kryptoslogic.com/advisories/2010/kryptoslogic-ibm-tivoli-dsmtca.txt","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"404 Page not found - Kryptos Logic","mime":"text/plain","httpstatus":"404","archivestatus":"200"},{"url":"http://www.exploit-db.com/exploits/15745","name":"http://www.exploit-db.com/exploits/15745","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory","VDB Entry"],"title":"IBM Tivoli Storage Manager (TSM) Local Root","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.kryptoslogic.com/advisories/2010/kryptoslogic-ibm-tivoli-dsmtca-exploit.c","name":"http://www.kryptoslogic.com/advisories/2010/kryptoslogic-ibm-tivoli-dsmtca-exploit.c","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Exploit"],"title":"404 Page not found - Kryptos Logic","mime":"text/x-c","httpstatus":"404","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2010-4604","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2010-4604","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2010","cve_id":"4604","vulnerable":"1","versionEndIncluding":"5.3.6.7","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"tivoli_storage_manager","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"4604","vulnerable":"1","versionEndIncluding":"5.4.3.3","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"tivoli_storage_manager","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"4604","vulnerable":"1","versionEndIncluding":"5.5.2.7","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"tivoli_storage_manager","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"4604","vulnerable":"1","versionEndIncluding":"6.1.3","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"tivoli_storage_manager","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"4604","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"linux","cpe5":"linux_kernel","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T03:51:17.700Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"1024901","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1024901"},{"name":"IC65491","tags":["vendor-advisory","x_refsource_AIXAPAR","x_transferred"],"url":"http://www-01.ibm.com/support/docview.wss?uid=swg1IC65491"},{"name":"ADV-2010-3251","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2010/3251"},{"name":"15745","tags":["exploit","x_refsource_EXPLOIT-DB","x_transferred"],"url":"http://www.exploit-db.com/exploits/15745"},{"name":"42639","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/42639"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.kryptoslogic.com/advisories/2010/kryptoslogic-ibm-tivoli-dsmtca.txt"},{"name":"20101215 Kryptos Logic Advisory: IBM Tivoli Storage Manager (TSM) Local Root","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/515263/100/0/threaded"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.kryptoslogic.com/advisories/2010/kryptoslogic-ibm-tivoli-dsmtca-exploit.c"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.ibm.com/support/docview.wss?uid=swg21454745"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2010-12-14T00:00:00.000Z","descriptions":[{"lang":"en","value":"Stack-based buffer overflow in the GeneratePassword function in dsmtca (aka the Trusted Communications Agent or TCA) in the backup-archive client in IBM Tivoli Storage Manager (TSM) 5.3.x before 5.3.6.10, 5.4.x before 5.4.3.4, 5.5.x before 5.5.2.10, and 6.1.x before 6.1.3.1 on Unix and Linux allows local users to gain privileges by specifying a long LANG environment variable, and then sending a request over a pipe."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-10T18:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"1024901","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1024901"},{"name":"IC65491","tags":["vendor-advisory","x_refsource_AIXAPAR"],"url":"http://www-01.ibm.com/support/docview.wss?uid=swg1IC65491"},{"name":"ADV-2010-3251","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2010/3251"},{"name":"15745","tags":["exploit","x_refsource_EXPLOIT-DB"],"url":"http://www.exploit-db.com/exploits/15745"},{"name":"42639","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/42639"},{"tags":["x_refsource_MISC"],"url":"http://www.kryptoslogic.com/advisories/2010/kryptoslogic-ibm-tivoli-dsmtca.txt"},{"name":"20101215 Kryptos Logic Advisory: IBM Tivoli Storage Manager (TSM) Local Root","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/515263/100/0/threaded"},{"tags":["x_refsource_MISC"],"url":"http://www.kryptoslogic.com/advisories/2010/kryptoslogic-ibm-tivoli-dsmtca-exploit.c"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.ibm.com/support/docview.wss?uid=swg21454745"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2010-4604","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Stack-based buffer overflow in the GeneratePassword function in dsmtca (aka the Trusted Communications Agent or TCA) in the backup-archive client in IBM Tivoli Storage Manager (TSM) 5.3.x before 5.3.6.10, 5.4.x before 5.4.3.4, 5.5.x before 5.5.2.10, and 6.1.x before 6.1.3.1 on Unix and Linux allows local users to gain privileges by specifying a long LANG environment variable, and then sending a request over a pipe."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"1024901","refsource":"SECTRACK","url":"http://securitytracker.com/id?1024901"},{"name":"IC65491","refsource":"AIXAPAR","url":"http://www-01.ibm.com/support/docview.wss?uid=swg1IC65491"},{"name":"ADV-2010-3251","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2010/3251"},{"name":"15745","refsource":"EXPLOIT-DB","url":"http://www.exploit-db.com/exploits/15745"},{"name":"42639","refsource":"SECUNIA","url":"http://secunia.com/advisories/42639"},{"name":"http://www.kryptoslogic.com/advisories/2010/kryptoslogic-ibm-tivoli-dsmtca.txt","refsource":"MISC","url":"http://www.kryptoslogic.com/advisories/2010/kryptoslogic-ibm-tivoli-dsmtca.txt"},{"name":"20101215 Kryptos Logic Advisory: IBM Tivoli Storage Manager (TSM) Local Root","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/515263/100/0/threaded"},{"name":"http://www.kryptoslogic.com/advisories/2010/kryptoslogic-ibm-tivoli-dsmtca-exploit.c","refsource":"MISC","url":"http://www.kryptoslogic.com/advisories/2010/kryptoslogic-ibm-tivoli-dsmtca-exploit.c"},{"name":"http://www.ibm.com/support/docview.wss?uid=swg21454745","refsource":"CONFIRM","url":"http://www.ibm.com/support/docview.wss?uid=swg21454745"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2010-4604","datePublished":"2010-12-29T17:27:00.000Z","dateReserved":"2010-12-29T00:00:00.000Z","dateUpdated":"2024-08-07T03:51:17.700Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2010-12-29 18:00:03","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["CWE-787","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:C/I:C/A:C","baseScore":7.2,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":3.9,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:tivoli_storage_manager:*:*:*:*:*:*:*:*","versionStartIncluding":"5.3.0","versionEndIncluding":"5.3.6.7","matchCriteriaId":"8D495CFC-A290-4752-A53B-D5A37C714144"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:tivoli_storage_manager:*:*:*:*:*:*:*:*","versionStartIncluding":"5.4.0","versionEndIncluding":"5.4.3.3","matchCriteriaId":"9BE1FE8D-36F2-4039-B64C-F106F9F86D93"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:tivoli_storage_manager:*:*:*:*:*:*:*:*","versionStartIncluding":"5.5.0","versionEndIncluding":"5.5.2.7","matchCriteriaId":"17F20A7F-0BC1-4247-B4F8-F7B1BAF3E237"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:tivoli_storage_manager:*:*:*:*:*:*:*:*","versionStartIncluding":"6.1.0","versionEndIncluding":"6.1.3","matchCriteriaId":"951E603F-D67E-4607-9D84-064BDB63BF90"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*","matchCriteriaId":"703AF700-7A70-47E2-BC3A-7FD03B3CA9C1"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2010","CveId":"4604","Ordinal":"1","Title":"CVE-2010-4604","CVE":"CVE-2010-4604","Year":"2010"},"notes":[{"CveYear":"2010","CveId":"4604","Ordinal":"1","NoteData":"Stack-based buffer overflow in the GeneratePassword function in dsmtca (aka the Trusted Communications Agent or TCA) in the backup-archive client in IBM Tivoli Storage Manager (TSM) 5.3.x before 5.3.6.10, 5.4.x before 5.4.3.4, 5.5.x before 5.5.2.10, and 6.1.x before 6.1.3.1 on Unix and Linux allows local users to gain privileges by specifying a long LANG environment variable, and then sending a request over a pipe.","Type":"Description","Title":"CVE-2010-4604"},{"CveYear":"2010","CveId":"4604","Ordinal":"2","NoteData":"2010-12-29","Type":"Other","Title":"Published"},{"CveYear":"2010","CveId":"4604","Ordinal":"3","NoteData":"2018-10-10","Type":"Other","Title":"Modified"}]}}}