CVE-2007-4880: Buffer Overflow
Buffer overflow in the Client Acceptor Daemon (CAD), dsmcad.exe, in certain IBM Tivoli Storage Manager (TSM) clients 5.1 before 5.1.8.1, 5.2 before 5.2.5.2, 5.3 before 5.3.5.3, and 5.4 before 5.4.1.2 allows remote attackers to execute arbitrary code via crafted HTTP headers, aka IC52905.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-4880?
CVE-2007-4880 has a medium severity rating due to its potential for remote code execution.
How do I fix CVE-2007-4880?
To fix CVE-2007-4880, upgrade to the fixed versions of IBM Tivoli Storage Manager Client: 5.1.8.1, 5.2.5.2, 5.3.5.3, or 5.4.1.2.
What versions of IBM Tivoli Storage Manager are affected by CVE-2007-4880?
IBM Tivoli Storage Manager Client versions 5.1 before 5.1.8.1, 5.2 before 5.2.5.2, 5.3 before 5.3.5.3, and 5.4 before 5.4.1.2 are affected by CVE-2007-4880.
Can CVE-2007-4880 be exploited remotely?
Yes, CVE-2007-4880 can be exploited remotely via crafted HTTP headers sent to the affected client.
What type of vulnerability is CVE-2007-4880?
CVE-2007-4880 is classified as a buffer overflow vulnerability.