CVE-2008-4563
Last modified
CVE-2008-4563 is a vulnerability of currently unknown severity. Heap-based buffer overflow in adsmdll.dll 5.3.7.7296, as used by the daemon (dsmsvc.exe) in the backup server in IBM Tivoli Storage Manager (TSM) Express 5.3.7.3 and earlier and TSM 5.2, 5.3 before 5.3.6.0, and 5.4.0.0 through 5.4.4.0, allows remote attackers to execute arbitrary code via a crafted length value.. EPSS estimates a 27.02% chance of exploitation in the next 30 days.
Description
Heap-based buffer overflow in adsmdll.dll 5.3.7.7296, as used by the daemon (dsmsvc.exe) in the backup server in IBM Tivoli Storage Manager (TSM) Express 5.3.7.3 and earlier and TSM 5.2, 5.3 before 5.3.6.0, and 5.4.0.0 through 5.4.4.0, allows remote attackers to execute arbitrary code via a crafted length value.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Tivoli Storage Manager | 5.2 |
| Ibm | Tivoli Storage Manager | 5.3 |
| Ibm | Tivoli Storage Manager | 5.3.0 |
| Ibm | Tivoli Storage Manager | 5.3.1 |
| Ibm | Tivoli Storage Manager | 5.3.2 |
| Ibm | Tivoli Storage Manager | 5.3.2.4 |
| Ibm | Tivoli Storage Manager | 5.3.3 |
| Ibm | Tivoli Storage Manager | 5.3.4 |
| Ibm | Tivoli Storage Manager | 5.3.5.1 |
| Ibm | Tivoli Storage Manager | 5.4.0 |
| Ibm | Tivoli Storage Manager | 5.4.1 |
| Ibm | Tivoli Storage Manager | 5.4.2 |
| Ibm | Tivoli Storage Manager | 5.4.2.2 |
| Ibm | Tivoli Storage Manager | 5.4.2.3 |
| Ibm | Tivoli Storage Manager | 5.4.2.4 |
| Ibm | Tivoli Storage Manager | 5.4.4.0 |
| Ibm | Tivoli Storage Manager Express | 5.3 |
| Ibm | Tivoli Storage Manager Express | 5.3.3.0 |
| Ibm | Tivoli Storage Manager Express | 5.3.6.4 |
| Ibm | Tivoli Storage Manager Express | 5.3.7.3 |
References
- http://secunia.com/advisories/34245Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21377388Patch, Vendor Advisory
- http://www.vupen.com/english/advisories/2009/0669Vendor Advisory
- http://secunia.com/advisories/34245Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21377388Patch, Vendor Advisory
- http://www.vupen.com/english/advisories/2009/0669Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2008-4563?
How severe is CVE-2008-4563?
How do I fix CVE-2008-4563?
Are you affected by CVE-2008-4563?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
