Record summary

CVE-2010-4604 has a selected CVSS score of 7.2; EIP currently links 1 catalogued exploit.

Description

Stack-based buffer overflow in the GeneratePassword function in dsmtca (aka the Trusted Communications Agent or TCA) in the backup-archive client in IBM Tivoli Storage Manager (TSM) 5.3.x before 5.3.6.10, 5.4.x before 5.4.3.4, 5.5.x before 5.5.2.10, and 6.1.x before 6.1.3.1 on Unix and Linux allows local users to gain privileges by specifying a long LANG environment variable, and then sending a request over a pipe.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBIBM Tivoli Storage Manager (TSM) - Local Privilege EscalationExploitDB exploitby Kryptos LogicNot analyzed1 file
ExploitDB

PoC details

References

10