CVE-2009-3854: Buffer Overflow
Published Nov 4, 2009
·Updated
Buffer overflow in the traditional client scheduler in the client in IBM Tivoli Storage Manager (TSM) 5.3 before 5.3.6.7 and 5.4 before 5.4.2 allows remote attackers to execute arbitrary code via unspecified vectors.
Affected Software
18 affected components
IBM Tivoli Storage Manager=5.3.6.3
IBM Tivoli Storage Manager=5.3.6.1
IBM Tivoli Storage Manager=5.3.6.6
IBM Tivoli Storage Manager=5.3.2.4
IBM Tivoli Storage Manager=5.3.4
IBM Tivoli Storage Manager=5.5.0
IBM Tivoli Storage Manager=5.3.6.2
IBM Tivoli Storage Manager=5.3.1
IBM Tivoli Storage Manager=5.3.3
IBM Tivoli Storage Manager=5.3.0
IBM Tivoli Storage Manager=5.4.1
IBM Tivoli Storage Manager=5.4.0
IBM Tivoli Storage Manager=5.3.2
IBM Tivoli Storage Manager=5.3.6.4
IBM Tivoli Storage Manager=5.3.5.1
IBM Tivoli Storage Manager=5.3
IBM Tivoli Storage Manager=5.2.5.3
IBM Tivoli Storage Manager=5.3.6.5
Remediation
Patch Available
Patch Available
Event History
Nov 4, 2009
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-3854?
CVE-2009-3854 is considered a critical vulnerability due to the potential for remote code execution.
2
How do I fix CVE-2009-3854?
To mitigate CVE-2009-3854, update IBM Tivoli Storage Manager to version 5.3.6.7 or later, or 5.4.2 or later.
3
Which versions are affected by CVE-2009-3854?
CVE-2009-3854 affects IBM Tivoli Storage Manager versions 5.3.6.1 through 5.3.6.6 and 5.4.0 through 5.4.1.
4
What type of vulnerability is CVE-2009-3854?
CVE-2009-3854 is classified as a buffer overflow vulnerability in the IBM Tivoli Storage Manager.
5
Can CVE-2009-3854 be exploited remotely?
Yes, CVE-2009-3854 can be exploited by remote attackers to execute arbitrary code on the system.