Overview
A buffer overflow condition exists in certain login fields on the IBM Tivoli Storage manager server. If successfully exploited, this vulnerability would allow an attacker to
cause a denial-of-service condition or possibly execute arbitrary code
Description
The IBM Tivoli Storage Manager (TSM) is a remote backup software package that runs on clients and servers. TSM clients must register and authenticate to servers before performing backup functions. The SmExecuteWdsfSession() function is used during the initial part of the authentication process. From a public vulnerability report, a buffer overflow vulnerability exists in this function. The overflow can be triggered during the processing of two separate fields sent in the request, both of which are copied into fixed sized buffers, without any validation of their lengths. |
Impact
A remote, unauthenticated attacker may be able to cause the TSM server to crash, thereby creating a denial-of-service condition. It may also be possible for the attacker to execute arbitrary code in the context of the TSM server. |
Solution
Update The update provided by IBM may address this issue. |
|
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
Acknowledgements
This report was based on information from Tipping Point Advisory TSRT-06-14.
This document was written by Ryan Giobbi.
Other Information
CVE IDs: | CVE-2006-5855 |
Severity Metric: | 0.14 |
Date Public: | 2006-12-04 |
Date First Published: | 2007-02-05 |
Date Last Updated: | 2007-02-09 15:49 UTC |
Document Revision: | 29 |