CVE-2009-3853
high · 9.3Stack-based buffer overflow in the client acceptor daemon (CAD) scheduler in the client in IBM Tivoli Storage Manager (TSM) 5.3 before 5.3.6.7, 5.4 before 5.4.3, 5.5 before 5.5.2.2, and 6.1 before 6.1.0.2, and TSM Express 5.3.3.0 through 5.3.6.6, allows remote attackers to execute arbitrary code via crafted data in a TCP packet.
9.3
CVSS
36.7%
EPSS (exploit prob.)
98th
EPSS percentile
2009-11-04
Published
AV:N/AC:M/Au:N/C:C/I:C/A:C
Weaknesses
CWE-119
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| ibm | tivoli_storage_manager | 5.2.5.3 |
| ibm | tivoli_storage_manager | 5.3 |
| ibm | tivoli_storage_manager | 5.3.0 |
| ibm | tivoli_storage_manager | 5.3.1 |
| ibm | tivoli_storage_manager | 5.3.2 |
| ibm | tivoli_storage_manager | 5.3.2.4 |
| ibm | tivoli_storage_manager | 5.3.3 |
| ibm | tivoli_storage_manager | 5.3.3 |
| ibm | tivoli_storage_manager | 5.3.4 |
| ibm | tivoli_storage_manager | 5.3.4 |
| ibm | tivoli_storage_manager | 5.3.5 |
| ibm | tivoli_storage_manager | 5.3.5.1 |
| ibm | tivoli_storage_manager | 5.3.6 |
| ibm | tivoli_storage_manager | 5.3.6.1 |
| ibm | tivoli_storage_manager | 5.3.6.2 |
| ibm | tivoli_storage_manager | 5.3.6.3 |
| ibm | tivoli_storage_manager | 5.3.6.4 |
| ibm | tivoli_storage_manager | 5.3.6.5 |
| ibm | tivoli_storage_manager | 5.3.6.6 |
| ibm | tivoli_storage_manager | 5.3.6.6 |
| ibm | tivoli_storage_manager | 5.4.0 |
| ibm | tivoli_storage_manager | 5.4.1 |
| ibm | tivoli_storage_manager | 5.4.2 |
| ibm | tivoli_storage_manager | 5.5.0 |
| ibm | tivoli_storage_manager | 5.5.1 |
| ibm | tivoli_storage_manager | 5.5.2 |
| ibm | tivoli_storage_manager | 6.1.0 |
Check a specific version with /api/v1/cve/match.
References
- http://secunia.com/advisories/32534
- http://secunia.com/secunia_research/2008-51/
- http://securitytracker.com/id?1023136
- http://www-01.ibm.com/support/docview.wss?uid=swg1IC61036
- http://www-01.ibm.com/support/docview.wss?uid=swg21405562
- http://www.securityfocus.com/archive/1/507654/100/0/threaded
- http://www.vupen.com/english/advisories/2009/3132
- http://secunia.com/advisories/32534
- http://secunia.com/secunia_research/2008-51/
- http://securitytracker.com/id?1023136
- http://www-01.ibm.com/support/docview.wss?uid=swg1IC61036
- http://www-01.ibm.com/support/docview.wss?uid=swg21405562
- http://www.securityfocus.com/archive/1/507654/100/0/threaded
- http://www.vupen.com/english/advisories/2009/3132
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2009-3853