APP: IBM Tivoli Storage Manager Client CAD Service Buffer Overflow
A buffer overflow vulnerability exists in IBM Tivoli Storage Manager Client software. The vulnerability is due to a boundary error in the Client Acceptor Daemon (CAD) service while processing a specially crafted packet. Remote unauthenticated attackers can exploit this vulnerability to inject and execute arbitrary code on the target system. Successful exploitation of this vulnerability would allow for arbitrary code execution with the SYSTEM privileges of the CAD service. If the attack is not successful, the vulnerable service may terminate abnormally due to memory corruption.
Extended Description
IBM Tivoli Storage Manager is prone to multiple buffer-overflow issues and an unauthorized-access issue. Attackers can exploit these issues to cause a denial-of-service condition, to execute arbitrary code, and to read, copy, edit, or delete files on a victim's computer. Other attacks may also be possible.
Affected Products
Ibm tivoli_storage_manager
References
BugTraq: 36916
CVE: CVE-2009-3853
URL: http://www-01.ibm.com/support/docview.wss?uid=swg21405562
srx-branch-12.3
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-branch-19.4
vsrx-19.4
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx3bsd-19.4
srx-19.4
vsrx-12.3
vmx-19.3
vsrx-19.2
srx-12.3
Ibm
9.3