First published: Fri Sep 28 2007(Updated: )
Buffer overflow in the Client Acceptor Daemon (CAD), dsmcad.exe, in certain IBM Tivoli Storage Manager (TSM) clients 5.1 before 5.1.8.1, 5.2 before 5.2.5.2, 5.3 before 5.3.5.3, and 5.4 before 5.4.1.2 allows remote attackers to execute arbitrary code via crafted HTTP headers, aka IC52905.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Tivoli Storage Manager Client | =5.1 | |
IBM Tivoli Storage Manager Client | =5.1.8.0 | |
IBM Tivoli Storage Manager Client | =5.2 | |
IBM Tivoli Storage Manager Client | =5.2.5.1 | |
IBM Tivoli Storage Manager Client | =5.3 | |
IBM Tivoli Storage Manager Client | =5.3.5.2 | |
IBM Tivoli Storage Manager Client | =5.4 | |
IBM Tivoli Storage Manager Client | =5.4.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-4880 has a medium severity rating due to its potential for remote code execution.
To fix CVE-2007-4880, upgrade to the fixed versions of IBM Tivoli Storage Manager Client: 5.1.8.1, 5.2.5.2, 5.3.5.3, or 5.4.1.2.
IBM Tivoli Storage Manager Client versions 5.1 before 5.1.8.1, 5.2 before 5.2.5.2, 5.3 before 5.3.5.3, and 5.4 before 5.4.1.2 are affected by CVE-2007-4880.
Yes, CVE-2007-4880 can be exploited remotely via crafted HTTP headers sent to the affected client.
CVE-2007-4880 is classified as a buffer overflow vulnerability.