Overview
A buffer overflow condition exists in the IBM Tivoli Storage manager server. If successfully exploited, this vulnerability would allow an attacker to cause a denial-of-service condition or possibly execute arbitrary code.
Description
The IBM Tivoli Storage Manager (TSM) is a remote backup software package that runs on clients and servers. TSM clients must register and authenticate to servers before performing backup functions. From TippingPoint Advisory TSRT-06-14: |
Impact
A remote, unauthenticated attacker may be able to cause the TSM server to crash, thereby creating a denial-of-service condition. It may also be possible for the attacker to execute arbitrary code in the context of the TSM server. |
Solution
Update An update provided by IBM may address this issue. |
|
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
Acknowledgements
This report was based on information from Tipping Point Advisory TSRT-06-14.
This document was written by Ryan Giobbi.
Other Information
CVE IDs: | CVE-2006-5855 |
Severity Metric: | 0.36 |
Date Public: | 2006-12-04 |
Date First Published: | 2007-02-05 |
Date Last Updated: | 2007-02-09 15:49 UTC |
Document Revision: | 30 |