CVE-2021-29672

high

Description

IBM Spectrum Protect Client 8.1.0.0-8 through 1.11.0 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking when processing the current locale settings. A local attacker could overflow a buffer and execute arbitrary code on the system with elevated privileges or cause the application to crash. IBM X-Force ID: 199479

References

https://www.ibm.com/support/pages/node/6445497

https://security.gentoo.org/glsa/202209-02

https://exchange.xforce.ibmcloud.com/vulnerabilities/199479

Details

Source: Mitre, NVD

Published: 2021-04-26

Updated: 2022-09-30

Risk Information

CVSS v2

Base Score: 7.2

Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C

Severity: High

CVSS v3

Base Score: 7.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Severity: High