CVE-2008-4563

Heap-based buffer overflow in adsmdll.dll 5.3.7.7296, as used by the daemon (dsmsvc.exe) in the backup server in IBM Tivoli Storage Manager (TSM) Express 5.3.7.3 and earlier and TSM 5.2, 5.3 before 5.3.6.0, and 5.4.0.0 through 5.4.4.0, allows remote attackers to execute arbitrary code via a crafted length value.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*
OR cpe:2.3:a:ibm:tivoli_storage_manager:5.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:tivoli_storage_manager:5.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:tivoli_storage_manager:5.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:tivoli_storage_manager:5.3.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:tivoli_storage_manager:5.3.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:tivoli_storage_manager:5.3.2.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:tivoli_storage_manager:5.3.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:tivoli_storage_manager:5.3.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:tivoli_storage_manager:5.3.5.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:tivoli_storage_manager:5.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:tivoli_storage_manager:5.4.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:tivoli_storage_manager:5.4.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:tivoli_storage_manager:5.4.2.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:tivoli_storage_manager:5.4.2.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:tivoli_storage_manager:5.4.2.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:tivoli_storage_manager:5.4.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:tivoli_storage_manager_express:5.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:tivoli_storage_manager_express:5.3.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:tivoli_storage_manager_express:5.3.6.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:tivoli_storage_manager_express:5.3.7.3:*:*:*:*:*:*:*

History

21 Nov 2024, 00:51

Type Values Removed Values Added
References () http://archives.neohapsis.com/archives/fulldisclosure/2009-03/0192.html - () http://archives.neohapsis.com/archives/fulldisclosure/2009-03/0192.html -
References () http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=775 - () http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=775 -
References () http://osvdb.org/52617 - () http://osvdb.org/52617 -
References () http://secunia.com/advisories/34245 - Vendor Advisory () http://secunia.com/advisories/34245 - Vendor Advisory
References () http://securitytracker.com/id?1021837 - () http://securitytracker.com/id?1021837 -
References () http://www-01.ibm.com/support/docview.wss?uid=swg21377388 - Patch, Vendor Advisory () http://www-01.ibm.com/support/docview.wss?uid=swg21377388 - Patch, Vendor Advisory
References () http://www.securityfocus.com/bid/34077 - () http://www.securityfocus.com/bid/34077 -
References () http://www.vupen.com/english/advisories/2009/0669 - Vendor Advisory () http://www.vupen.com/english/advisories/2009/0669 - Vendor Advisory
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/49188 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/49188 -

Information

Published : 2009-03-11 14:19

Updated : 2024-11-21 00:51


NVD link : CVE-2008-4563

Mitre link : CVE-2008-4563

CVE.ORG link : CVE-2008-4563


JSON object : View

Products Affected

ibm

  • tivoli_storage_manager_express
  • tivoli_storage_manager

microsoft

  • windows
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer