CVE-2010-3758
Multiple stack-based buffer overflows in FastBackServer.exe in the Server in IBM Tivoli Storage Manager (TSM) FastBack 5.5.0.0 through 5.5.6.0 and 6.1.0.0 through 6.1.0.1 allow remote attackers to execute arbitrary code via vectors involving the (1)…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (6.66%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Multiple stack-based buffer overflows in FastBackServer.exe in the Server in IBM Tivoli Storage Manager (TSM) FastBack 5.5.0.0 through 5.5.6.0 and 6.1.0.0 through 6.1.0.1 allow remote attackers to execute arbitrary code via vectors involving the (1) AGI_SendToLog (aka _SendToLog) function; the (2) group, (3) workgroup, or (4) domain name field to the USER_S_AddADGroup function; the (5) user_path variable to the FXCLI_checkIndexDBLocation function; or (6) the _AGI_S_ActivateLTScriptReply (aka ActivateLTScriptReply) function. NOTE: this might overlap CVE-2010-3059.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 6.66% probability · 93th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-94
- Affected
- ibm/tivoli storage manager fastback
- Source
- cve@mitre.org
References
- http://www-01.ibm.com/support/docview.wss?uid=swg1IC69883Vendor Advisory
- http://www.ibm.com/support/docview.wss?uid=swg21443820Vendor Advisory
- http://www.securityfocus.com/archive/1/514059/100/0/threaded
- http://www.securityfocus.com/archive/1/514067/100/0/threaded
- http://www.securityfocus.com/archive/1/514072/100/0/threaded
- http://www.securityfocus.com/archive/1/514078/100/0/threaded
- http://zerodayinitiative.com/advisories/ZDI-10-180/
- http://zerodayinitiative.com/advisories/ZDI-10-181/
- http://zerodayinitiative.com/advisories/ZDI-10-183/
- http://zerodayinitiative.com/advisories/ZDI-10-184/
- http://www-01.ibm.com/support/docview.wss?uid=swg1IC69883Vendor Advisory
- http://www.ibm.com/support/docview.wss?uid=swg21443820Vendor Advisory
- http://www.securityfocus.com/archive/1/514059/100/0/threaded
- http://www.securityfocus.com/archive/1/514067/100/0/threaded
- http://www.securityfocus.com/archive/1/514072/100/0/threaded
- http://www.securityfocus.com/archive/1/514078/100/0/threaded
- http://zerodayinitiative.com/advisories/ZDI-10-180/
- http://zerodayinitiative.com/advisories/ZDI-10-181/
- http://zerodayinitiative.com/advisories/ZDI-10-183/
- http://zerodayinitiative.com/advisories/ZDI-10-184/
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.