CVE-2008-5982: Critical severity BMC PATROL Agent vulnerability
Format string vulnerability in BMC PATROL Agent before 3.7.30 allows remote attackers to execute arbitrary code via format string specifiers in an invalid version number to TCP port 3181, which are not properly handled when writing a log message.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
BMC PATROL Agentto a version that resolves this vulnerability.Fixed in 3.7.30 - Compensating control
Block or restrict access to TCP port 3181 from untrusted networks (e.g., via firewall or network ACLs) to prevent remote submission of crafted version strings to the BMC PATROL Agent.
Event History
Frequently Asked Questions
What is the severity of CVE-2008-5982?
CVE-2008-5982 is considered to be a high severity vulnerability due to its potential to allow arbitrary code execution.
How do I fix CVE-2008-5982?
To fix CVE-2008-5982, update the BMC PATROL Agent to version 3.7.30 or later, which addresses the format string vulnerability.
What type of vulnerability is CVE-2008-5982?
CVE-2008-5982 is a format string vulnerability that can be exploited through improperly handled log message formats.
Which versions of BMC PATROL Agent are affected by CVE-2008-5982?
CVE-2008-5982 affects BMC PATROL Agent versions up to 3.7, including specific versions like 3.3.00, 3.4.00, 3.4.11, and lower.
Can CVE-2008-5982 be exploited remotely?
Yes, CVE-2008-5982 can be exploited remotely via TCP port 3181 by sending malformed version number requests.