IBM Tivoli Storage Manager Long Username Buffer Overflow Vulnerability
BID:4500
Info
IBM Tivoli Storage Manager Long Username Buffer Overflow Vulnerability
| Bugtraq ID: | 4500 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2002-0541 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 11 2002 12:00AM |
| Updated: | Jul 11 2009 11:56AM |
| Credit: | Discovered by Patrik Karlsson <[email protected]> and Jonas Ländin <[email protected]>. |
| Vulnerable: |
IBM Tivoli Storage Manager 4.2.1 IBM Tivoli Storage Manager 4.2 |
| Not Vulnerable: |
IBM Tivoli Storage Manager 4.2.1 .15 |
Discussion
IBM Tivoli Storage Manager Long Username Buffer Overflow Vulnerability
A buffer overflow condition has been discovered in IBM Tivoli Storage Manager.
If an unusually long username is supplied to the HTTP port of the server, a buffer overflow could occur. As a result, it is possible to overwrite stack variables, including the return address, and cause the execution of arbitrary code.
A buffer overflow condition has been discovered in IBM Tivoli Storage Manager.
If an unusually long username is supplied to the HTTP port of the server, a buffer overflow could occur. As a result, it is possible to overwrite stack variables, including the return address, and cause the execution of arbitrary code.
Exploit / POC
IBM Tivoli Storage Manager Long Username Buffer Overflow Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
IBM Tivoli Storage Manager Long Username Buffer Overflow Vulnerability
Solution:
The discoverer of this issue has reported that version 4.2.1.15 addresses this issue.
IBM Tivoli Storage Manager 4.2
IBM Tivoli Storage Manager 4.2.1
Solution:
The discoverer of this issue has reported that version 4.2.1.15 addresses this issue.
IBM Tivoli Storage Manager 4.2
-
IBM TSMSRV42115_HP
HP
ftp://ftp.software.ibm.com/storage/tivoli-storage-management/patches/s erver/HP-UX/4.2.1.15/TSMSRV42115_HP.tar -
IBM TSMSRV42115_WIN
Windows NT & Windows 2000
ftp://ftp.software.ibm.com/storage/tivoli-storage-management/patches/s erver/NT/4.2.1.15/TSMSRV42115_WIN.exe -
IBM TSMSRVAIX04_02_01_15
AIX
ftp://ftp.software.ibm.com/storage/tivoli-storage-management/patches/s erver/AIX/4.2.1.15/TSMSRVAIX04_02_01_15.tar.gz
IBM Tivoli Storage Manager 4.2.1
-
IBM TSMSRV42115_HP
HP
ftp://ftp.software.ibm.com/storage/tivoli-storage-management/patches/s erver/HP-UX/4.2.1.15/TSMSRV42115_HP.tar -
IBM TSMSRV42115_WIN
Windows NT & Windows 2000
ftp://ftp.software.ibm.com/storage/tivoli-storage-management/patches/s erver/NT/4.2.1.15/TSMSRV42115_WIN.exe -
IBM TSMSRVAIX04_02_01_15
AIX
ftp://ftp.software.ibm.com/storage/tivoli-storage-management/patches/s erver/AIX/4.2.1.15/TSMSRVAIX04_02_01_15.tar.gz
References
IBM Tivoli Storage Manager Long Username Buffer Overflow Vulnerability
References:
References: