|
|
|
Credit:
The information has been provided by Dyon Balding.
|
|
Vulnerable Systems:
* IBM Tivoli Storage Manager Express Client version 5.3.6.2
1) A boundary error in a generic string handling function when parsing strings from request packets can be exploited to cause stack-based buffer overflow.
2) A boundary error when copying the NodeName from a request packet in dicuGetIdentifyRequest can be exploited to cause a stack-based buffer overflow. Successful exploitation allows execution of arbitrary code.
Patch Availability:
IBM (IC59513, IC59994, IC59779, IC59781):
http://www-01.ibm.com/support/docview.wss?uid=swg21384389
CVE Information:
CVE-2008-4828
Disclosure Timeline:
13/11/2008 - Vendor notified.
18/11/2008 - Vendor response.
20/11/2008 - Vendor asks for additional information.
20/11/2008 - Clarification of the two problems provided to the vendor.
26/11/2008 - Vendor provides status update.
02/02/2009 - Vendor provides status update.
24/02/2009 - Vendor provides status update.
31/03/2009 - Status update requested.
31/03/2009 - Vendor provides status update.
04/05/2009 - Public disclosure.
|
|
|
|