Intrusion Prevention

IBM.Tivoli.Storage.Manager.Requests.Handling.Buffer.Overflow

Description

This indicates an attempt to exploit a buffer overflow vulnerability in IBM Tivoli Storage Manager.
The vulnerability is caused by an error that occurs when the vulnerable software handles initial sign-on request network messages. It allows a remote attacker to execute arbitrary code via initial sign-on request network messages.
A remote unauthenticated attacker may exploit this flaw to cause denial of service, or inject and execute arbitrary code on the target host, normally with System privileges.

Affected Products

IBM Tivoli Storage Manager (TSM) before 5.2.9 and 5.3.x before 5.3.4

Impact

Denial of service.
System compromise.

Recommended Actions

Apply APAR IC50347, available from the IBM Support & downloads Web site.

CVE References

CVE-2006-5855