IBM Tivoli Storage Manager Express Backup Server Service (dsmsvc.exe) Packet Handling Remote Overflow

critical Nessus Plugin ID 29997

Synopsis

The remote backup service is affected by a buffer overflow issue.

Description

The version of Tivoli Storage Manager (TSM) Express installed on the remote host is prior to 5.3.7.3. It is, therefore, affected by a heap-based buffer overflow vulnerability that can be triggered by a user-supplied length value. This could allow an unauthenticated attacker to run arbitrary code on the host with SYSTEM privileges.

Solution

Upgrade to TSM Express 5.3.7.3 or later.

See Also

https://www.zerodayinitiative.com/advisories/ZDI-08-001/

https://seclists.org/fulldisclosure/2008/Jan/227

https://securitytracker.com/id?1019182

Plugin Details

Severity: Critical

ID: 29997

File Name: ibm_tsm_express_5_3_7_3.nasl

Version: 1.19

Type: remote

Agent: windows

Family: Windows

Published: 1/17/2008

Updated: 4/11/2022

Configuration: Enable thorough checks

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Information

CPE: cpe:/a:ibm:tivoli_storage_manager_express

Required KB Items: installed_sw/IBM Tivoli Storage Manager

Exploit Ease: No known exploits are available

Patch Publication Date: 1/14/2008

Reference Information

CVE: CVE-2008-0247

BID: 27235

CWE: 119