IBM Tivoli Storage Manager Express and Enterprise Server Remote Buffer Overflow Vulnerability
BID:34077
Info
IBM Tivoli Storage Manager Express and Enterprise Server Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 34077 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2008-4563 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 10 2009 12:00AM |
| Updated: | Mar 31 2009 07:56PM |
| Credit: | iDefense and Assurent Secure Technologies. |
| Vulnerable: |
IBM Tivoli Storage Manager Express 5.3.7 .3 IBM Tivoli Storage Manager Express 5.3 IBM Tivoli Storage Manager 5.4.4 .0 IBM Tivoli Storage Manager 5.4.2 .4 IBM Tivoli Storage Manager 5.4.2 .3 IBM Tivoli Storage Manager 5.4.2 .2 IBM Tivoli Storage Manager 5.3.6 .9 Express IBM Tivoli Storage Manager 5.3.6 .2 IBM Tivoli Storage Manager 5.3.6 .1 IBM Tivoli Storage Manager 5.3.4 IBM Tivoli Storage Manager 5.2.9 IBM Tivoli Storage Manager 5.2.5 .3 IBM Tivoli Storage Manager 5.2.5 .2 IBM Tivoli Storage Manager 5.2.4 IBM Tivoli Storage Manager 5.1.8 .2 IBM Tivoli Storage Manager 5.1.8 .1 IBM Tivoli Storage Manager 4.2.1 .32 IBM Tivoli Storage Manager 4.2.1 .15 IBM Tivoli Storage Manager 4.2.1 IBM Tivoli Storage Manager 4.2 IBM Tivoli Storage Manager 5.4 IBM Tivoli Storage Manager 5.3.5.1 IBM Tivoli Storage Manager 5.3.2.4 IBM Tivoli Storage Manager 5.3 |
| Not Vulnerable: |
IBM Tivoli Storage Manager 5.4.4 .1 |
Discussion
IBM Tivoli Storage Manager Express and Enterprise Server Remote Buffer Overflow Vulnerability
IBM Tivoli Storage Manager (TSM) Express and Enterprise servers are prone to a remote heap-based buffer-overflow vulnerability.
Successfully exploiting this issue would allow a remote attacker to corrupt memory and execute arbitrary code in the context of the vulnerable application.
IBM Tivoli Storage Manager (TSM) Express and Enterprise servers are prone to a remote heap-based buffer-overflow vulnerability.
Successfully exploiting this issue would allow a remote attacker to corrupt memory and execute arbitrary code in the context of the vulnerable application.
Exploit / POC
IBM Tivoli Storage Manager Express and Enterprise Server Remote Buffer Overflow Vulnerability
A working commercial exploit is available through VUPEN Security - Exploit and PoCs Service. This exploit is not otherwise publicly available or known to be circulating in the wild.
A working commercial exploit is available through VUPEN Security - Exploit and PoCs Service. This exploit is not otherwise publicly available or known to be circulating in the wild.
Solution / Fix
IBM Tivoli Storage Manager Express and Enterprise Server Remote Buffer Overflow Vulnerability
Solution:
The vendor has released an advisory and updates. Please see the references for more information.
Solution:
The vendor has released an advisory and updates. Please see the references for more information.
References
IBM Tivoli Storage Manager Express and Enterprise Server Remote Buffer Overflow Vulnerability
References:
References: