42639Third-party advisory
http://secunia.com/advisories/42639 CVE-2010-4604
IBM Tivoli Storage Manager (TSM) - Local Privilege Escalation
Record summary
CVE-2010-4604 has a selected CVSS score of 7.2; EIP currently links 1 catalogued exploit.
Description
Stack-based buffer overflow in the GeneratePassword function in dsmtca (aka the Trusted Communications Agent or TCA) in the backup-archive client in IBM Tivoli Storage Manager (TSM) 5.3.x before 5.3.6.10, 5.4.x before 5.4.3.4, 5.5.x before 5.5.2.10, and 6.1.x before 6.1.3.1 on Unix and Linux allows local users to gain privileges by specifying a long LANG environment variable, and then sending a request over a pipe.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBIBM Tivoli Storage Manager (TSM) - Local Privilege EscalationExploitDB exploitby Kryptos LogicNot analyzed1 file
References
101024901vdb entry
http://securitytracker.com/id?1024901 IC65491Vendor advisory
http://www-01.ibm.com/support/docview.wss?uid=swg1IC65491 15745exploit
http://www.exploit-db.com/exploits/15745 ibm.comConfirmation
http://www.ibm.com/support/docview.wss?uid=swg21454745 kryptoslogic.com
http://www.kryptoslogic.com/advisories/2010/kryptoslogic-ibm-tivoli-dsmtca-exploit.c kryptoslogic.com
http://www.kryptoslogic.com/advisories/2010/kryptoslogic-ibm-tivoli-dsmtca.txt 20101215 Kryptos Logic Advisory: IBM Tivoli Storage Manager (TSM) Local Rootmailing list
http://www.securityfocus.com/archive/1/515263/100/0/threaded ADV-2010-3251vdb entry
http://www.vupen.com/english/advisories/2010/3251 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2010-4604