CVE-2010-3755: Null Pointer Dereference
The DASReadBlockReply function in FastBackServer.exe in the Server in IBM Tivoli Storage Manager (TSM) FastBack 5.5.0.0 through 5.5.6.0 and 6.1.0.0 through 6.1.0.1 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via data in a TCP packet. NOTE: this might overlap CVE-2010-3060.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-3755?
CVE-2010-3755 is categorized as a denial of service vulnerability that can cause the daemon to crash.
How do I fix CVE-2010-3755?
To mitigate CVE-2010-3755, update IBM Tivoli Storage Manager FastBack to a version that is not affected, specifically versions after 6.1.0.1.
What versions are affected by CVE-2010-3755?
CVE-2010-3755 affects IBM Tivoli Storage Manager FastBack versions 5.5.0.0 to 5.5.6.0 and 6.1.0.0 to 6.1.0.1.
What causes the denial of service in CVE-2010-3755?
The denial of service in CVE-2010-3755 is caused by a NULL pointer dereference resulting from malformed data in a TCP packet.
Is there a workaround for CVE-2010-3755 if I cannot update?
As a temporary measure, consider implementing network filtering to block malicious TCP packets that may exploit CVE-2010-3755.