First published: Tue Oct 05 2010(Updated: )
FastBackMount.exe in the Mount service in IBM Tivoli Storage Manager (TSM) FastBack 5.5.0.0 through 5.5.6.0 and 6.1.0.0 through 6.1.0.1 writes a certain value to a memory location specified by a UDP packet field, which allows remote attackers to execute arbitrary code via multiple requests. NOTE: this might overlap CVE-2010-3058.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Tivoli Storage Manager FastBack | =5.5.0 | |
IBM Tivoli Storage Manager FastBack | =5.5.1 | |
IBM Tivoli Storage Manager FastBack | =5.5.2 | |
IBM Tivoli Storage Manager FastBack | =5.5.2.0 | |
IBM Tivoli Storage Manager FastBack | =5.5.3.0 | |
IBM Tivoli Storage Manager FastBack | =5.5.4.0 | |
IBM Tivoli Storage Manager FastBack | =5.5.5.0 | |
IBM Tivoli Storage Manager FastBack | =5.5.6.0 | |
IBM Tivoli Storage Manager FastBack | =6.1.0.0 | |
IBM Tivoli Storage Manager FastBack | =6.1.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-3759 is classified as a high severity vulnerability due to the potential for remote code execution.
To fix CVE-2010-3759, upgrade to a patched version of IBM Tivoli Storage Manager FastBack beyond 6.1.0.1.
The affected versions for CVE-2010-3759 include IBM Tivoli Storage Manager FastBack 5.5.0.0 to 5.5.6.0 and 6.1.0.0 to 6.1.0.1.
CVE-2010-3759 can be exploited by remote attackers to execute arbitrary code on the affected system.
There are no known workarounds for CVE-2010-3759; updating to a fixed version is the recommended mitigation.