CVE-2008-4828: Buffer Overflow
Multiple stack-based buffer overflows in dsmagent.exe in the Remote Agent Service in the IBM Tivoli Storage Manager (TSM) client 5.1.0.0 through 5.1.8.2, 5.2.0.0 through 5.2.5.3, 5.3.0.0 through 5.3.6.4, and 5.4.0.0 through 5.4.1.96, and the TSM Express client 5.3.3.0 through 5.3.6.4, allow remote attackers to execute arbitrary code via (1) a request packet that is not properly parsed by an unspecified "generic string handling function" or (2) a crafted NodeName in a dicuGetIdentifyRequest request packet, related to the (a) Web GUI and (b) Java GUI.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2008-4828?
CVE-2008-4828 has a critical severity level due to multiple stack-based buffer overflows found in the IBM Tivoli Storage Manager.
How do I fix CVE-2008-4828?
To mitigate CVE-2008-4828, upgrade the IBM Tivoli Storage Manager client to version 5.1.9 or later or apply the relevant patches provided by IBM.
What versions are affected by CVE-2008-4828?
CVE-2008-4828 affects IBM Tivoli Storage Manager client versions ranging from 5.1.0.0 to 5.4.1.96.
What impact can CVE-2008-4828 have on my system?
Exploitation of CVE-2008-4828 can lead to remote code execution, allowing an attacker unauthorized access to the affected system.
Is CVE-2008-4828 specific to certain IBM products?
Yes, CVE-2008-4828 specifically impacts the IBM Tivoli Storage Manager and Tivoli Storage Manager Express client applications.