RULE(RULE ID:322503)

Rule General Information
Release Date: 2019-07-06
Rule Name: IBM TSM dsmcad.exe Buffer Overflow Vulnerability (CVE-2007-4880)
Severity:
CVE ID:
Rule Protection Details
Description: Buffer overflow in the Client Acceptor Daemon (CAD), dsmcad.exe, in certain IBM Tivoli Storage Manager (TSM) clients 5.1 before 5.1.8.1, 5.2 before 5.2.5.2, 5.3 before 5.3.5.3, and 5.4 before 5.4.1.2 allows remote attackers to execute arbitrary code via crafted HTTP headers, aka IC52905.
Impact: A buffer overflow vulnerability can be triggered by an attacker in the context of the vulnerable product. Further attacks includes arbitrary code execution and denial of service.
Affected OS: Windows, Linux, FreeBSD, Solaris, Other Unix, Network Device, Mac OS, iOS, Android, Others
Reference: SecurityFocusBID:25743
http://securityreason.com/securityalert/3184
http://www.securityfocus.com/archive/1/480492
SecurityTrackerID:1018725
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
http://www.ibm.com/support/docview.wss?uid=swg24016838