First published: Tue Oct 05 2010(Updated: )
The _DAS_ReadBlockReply function in FastBackServer.exe in the Server in IBM Tivoli Storage Manager (TSM) FastBack 5.5.0.0 through 5.5.6.0 and 6.1.0.0 through 6.1.0.1 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via data in a TCP packet. NOTE: this might overlap CVE-2010-3060.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Tivoli Storage Manager FastBack | =5.5.0 | |
IBM Tivoli Storage Manager FastBack | =5.5.1 | |
IBM Tivoli Storage Manager FastBack | =5.5.2 | |
IBM Tivoli Storage Manager FastBack | =5.5.2.0 | |
IBM Tivoli Storage Manager FastBack | =5.5.3.0 | |
IBM Tivoli Storage Manager FastBack | =5.5.4.0 | |
IBM Tivoli Storage Manager FastBack | =5.5.5.0 | |
IBM Tivoli Storage Manager FastBack | =5.5.6.0 | |
IBM Tivoli Storage Manager FastBack | =6.1.0.0 | |
IBM Tivoli Storage Manager FastBack | =6.1.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-3755 is categorized as a denial of service vulnerability that can cause the daemon to crash.
To mitigate CVE-2010-3755, update IBM Tivoli Storage Manager FastBack to a version that is not affected, specifically versions after 6.1.0.1.
CVE-2010-3755 affects IBM Tivoli Storage Manager FastBack versions 5.5.0.0 to 5.5.6.0 and 6.1.0.0 to 6.1.0.1.
The denial of service in CVE-2010-3755 is caused by a NULL pointer dereference resulting from malformed data in a TCP packet.
As a temporary measure, consider implementing network filtering to block malicious TCP packets that may exploit CVE-2010-3755.