IBM Tivoli Storage Manager Client Acceptor Buffer Overflow Vulnerability
BID:4492
Info
IBM Tivoli Storage Manager Client Acceptor Buffer Overflow Vulnerability
| Bugtraq ID: | 4492 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2002-0541 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 11 2002 12:00AM |
| Updated: | Jul 11 2009 11:56AM |
| Credit: | Discovered by Patrik Karlsson <[email protected]> and Jonas Ländin <[email protected]>. |
| Vulnerable: |
IBM Tivoli Storage Manager 4.2.1 IBM Tivoli Storage Manager 4.2 |
| Not Vulnerable: |
IBM Tivoli Storage Manager 4.2.1 .32 |
Discussion
IBM Tivoli Storage Manager Client Acceptor Buffer Overflow Vulnerability
A buffer overflow condition has been discovered in IBM Tivoli Storage Manager.
The TSM Client Acceptor does not perform adequate bounds checking. As a result, it is possible to create a buffer overflow, this could result in the overwriting of stack variables, including the return address, and the execution of arbitrary code.
A buffer overflow condition has been discovered in IBM Tivoli Storage Manager.
The TSM Client Acceptor does not perform adequate bounds checking. As a result, it is possible to create a buffer overflow, this could result in the overwriting of stack variables, including the return address, and the execution of arbitrary code.
Exploit / POC
IBM Tivoli Storage Manager Client Acceptor Buffer Overflow Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
IBM Tivoli Storage Manager Client Acceptor Buffer Overflow Vulnerability
Solution:
The discoverer of this issue has reported that version 4.2.1.32 addresses this issue. However, the link provided doesn't appear to have this version available. Contact IBM support for further information on obtaining the fix.
Solution:
The discoverer of this issue has reported that version 4.2.1.32 addresses this issue. However, the link provided doesn't appear to have this version available. Contact IBM support for further information on obtaining the fix.
References
IBM Tivoli Storage Manager Client Acceptor Buffer Overflow Vulnerability
References:
References: