First published: Tue May 05 2009(Updated: )
Multiple stack-based buffer overflows in dsmagent.exe in the Remote Agent Service in the IBM Tivoli Storage Manager (TSM) client 5.1.0.0 through 5.1.8.2, 5.2.0.0 through 5.2.5.3, 5.3.0.0 through 5.3.6.4, and 5.4.0.0 through 5.4.1.96, and the TSM Express client 5.3.3.0 through 5.3.6.4, allow remote attackers to execute arbitrary code via (1) a request packet that is not properly parsed by an unspecified "generic string handling function" or (2) a crafted NodeName in a dicuGetIdentifyRequest request packet, related to the (a) Web GUI and (b) Java GUI.
Credit: PSIRT-CNA@flexerasoftware.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ibm Tivoli Storage Manager Client | =5.2.5.2 | |
Ibm Tivoli Storage Manager Client | =5.1 | |
Ibm Tivoli Storage Manager Express | =5.3.6.4 | |
Ibm Tivoli Storage Manager Client | =5.3.6.3 | |
Ibm Tivoli Storage Manager Client | =5.4.1.2 | |
Ibm Tivoli Storage Manager Express | =5.3.3.0 | |
Ibm Tivoli Storage Manager Client | =5.3 | |
Ibm Tivoli Storage Manager Client | =5.4.1.1 | |
Ibm Tivoli Storage Manager Client | =5.2.5.1 | |
Ibm Tivoli Storage Manager Client | =5.1.8.2 | |
Ibm Tivoli Storage Manager Client | =5.2.5.3 | |
Ibm Tivoli Storage Manager Client | =5.4.1.96 | |
Ibm Tivoli Storage Manager Client | =5.2 | |
Ibm Tivoli Storage Manager Client | =5.3.5.3 | |
Ibm Tivoli Storage Manager Client | =5.4 | |
Ibm Tivoli Storage Manager Client | =5.3.5.2 | |
Ibm Tivoli Storage Manager Client | =5.1.8.0 | |
Ibm Tivoli Storage Manager Express | =5.3 | |
Ibm Tivoli Storage Manager Client | =5.3.6.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-4828 has a critical severity level due to multiple stack-based buffer overflows found in the IBM Tivoli Storage Manager.
To mitigate CVE-2008-4828, upgrade the IBM Tivoli Storage Manager client to version 5.1.9 or later or apply the relevant patches provided by IBM.
CVE-2008-4828 affects IBM Tivoli Storage Manager client versions ranging from 5.1.0.0 to 5.4.1.96.
Exploitation of CVE-2008-4828 can lead to remote code execution, allowing an attacker unauthorized access to the affected system.
Yes, CVE-2008-4828 specifically impacts the IBM Tivoli Storage Manager and Tivoli Storage Manager Express client applications.