CVE-2010-3760: Null Pointer Dereference
FastBackMount.exe in the Mount service in IBM Tivoli Storage Manager (TSM) FastBack 5.5.0.0 through 5.5.6.0 and 6.1.0.0 through 6.1.0.1 does not properly handle a certain failure to allocate memory, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash, and recovery failure) by specifying a large size value within TCP packet data. NOTE: this might overlap CVE-2010-3061.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-3760?
CVE-2010-3760 is classified as a denial of service vulnerability due to its potential to crash the affected service.
How do I fix CVE-2010-3760?
To fix CVE-2010-3760, update the IBM Tivoli Storage Manager FastBack to a patched version that addresses this vulnerability.
Which versions are affected by CVE-2010-3760?
CVE-2010-3760 affects IBM Tivoli Storage Manager FastBack versions 5.5.0.0 through 5.5.6.0 and 6.1.0.0 through 6.1.0.1.
What type of attack can exploit CVE-2010-3760?
CVE-2010-3760 can be exploited by remote attackers causing a denial of service through a NULL pointer dereference.
Is CVE-2010-3760 still relevant today?
While CVE-2010-3760 is an older vulnerability, it remains relevant for organizations still using unpatched versions of the affected software.