Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2008-4801
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2008-4801

Description:
Heap-based buffer overflow in the Data Protection for SQL CAD service (aka dsmcat.exe) in the Client Acceptor Daemon (CAD) and the scheduler in the Backup-Archive client 5.1.0.0 through 5.1.8.1, 5.2.0.0 through 5.2.5.2, 5.3.0.0 through 5.3.6.1, 5.4.0.0 through 5.4.2.2, and 5.5.0.0 through 5.5.0.91 in IBM Tivoli Storage Manager (TSM); and the Backup-Archive client in TSM Express; allows remote attackers to execute arbitrary code by sending a large amount of crafted data to a TCP port.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/46208

ST
  1021122

SAID
  Secunia Advisory: SA32465

MISC
  http://www.zerodayinitiative.com/advisories/ZDI-08-071/

CONFIRM
  http://www-01.ibm.com/support/docview.wss?uid=swg21322623

BUGTRAQ
  http://www.securityfocus.com/archive/1/archive/1/497950/100/0/threaded

BID
  31988

AIXAPAR
  http://www-1.ibm.com/support/docview.wss?uid=swg1IC56773


Return to the previous page.