IBM Tivoli Storage Manager Agent Service Buffer Overflows
10 May 2009
Summary
Secunia Research has discovered two vulnerabilities in IBM Tivoli Storage Manager Agent Client (dsmagent.exe), which can be exploited by malicious people to compromise a vulnerable system.
Credit:
The information has been provided by Dyon Balding.
Vulnerable Systems:
* IBM Tivoli Storage Manager Express Client version 5.3.6.2
1) A boundary error in a generic string handling function when parsing strings from request packets can be exploited to cause stack-based buffer overflow.
2) A boundary error when copying the NodeName from a request packet in dicuGetIdentifyRequest can be exploited to cause a stack-based buffer overflow. Successful exploitation allows execution of arbitrary code.