>> IBM Tivoli Storage Manager Client Buffer Overflow Vulnerability
Title : IBM Tivoli Storage Manager Client Buffer Overflow Vulnerability VUPEN ID : VUPEN/ADV-2008-2969 CVE ID : CVE-2008-4801 CWE ID : CWE-119
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-10-30
Technical Description
A vulnerability has been identified in IBM Tivoli Storage Manager (TSM), which could be exploited by attackers to cause a denial of service or compromise a vulnerable system. This issue is caused by a buffer overflow error in the Client Acceptor Daemon (CAD) and the Backup-Archive client scheduler and scheduler service when the option SCHEDMODE is set to PROMPTED, which could be exploited by attackers to crash an affected client or execute arbitrary code.