Lucene search

K
ibmIBM2EC7D4DDDB5FD85C5BAFCD176CF5C944A33F5FFD6052CD98EFC071E5186A96D0
HistoryJun 17, 2018 - 3:30 p.m.

Security Bulletin: IBM Tivoli Storage Manager FastBack affected by Stack-Based Buffer Overflow Elevation of Privilege Vulnerability - CORRECTION

2018-06-1715:30:57
www.ibm.com
10

EPSS

0.805

Percentile

98.4%

Summary

The IBM Tivoli Storage Manager FastBack mount process is vulnerable to a stack-based buffer overflow. A local or remote attacker could overflow a buffer and execute arbitrary code on the system with root privileges or cause the application to crash. On November 21, 2016 this vulnerability was incorrectly reported as CVE-2016-6091. The correct CVE IDs for these vulnerabilities are CVE-2015-1897 and CVE-2015-0119.

Vulnerability Details

Please consult the security bulletins IBM Tivoli Storage Manager FastBack Stack-Based Buffer Overflow Elevation of Privilege Vulnerability (CVE-2015-1897)_ and IBM Tivoli Storage Manager FastBack Mount Remote Code Execution Vulnerability (CVE-2015-0119) _for vulnerability details and information about fixes.

Affected Products and Versions

IBM Tivoli Storage Manager FastBack Mount 6.1.11 and earlier.

Remediation/Fixes

Please consult the security bulletins IBM Tivoli Storage Manager FastBack Stack-Based Buffer Overflow Elevation of Privilege Vulnerability (CVE-2015-1897)_ and IBM Tivoli Storage Manager FastBack Mount Remote Code Execution Vulnerability (CVE-2015-0119) _for information on applying the appropriate fixes.

Workarounds and Mitigations

None

EPSS

0.805

Percentile

98.4%

Related for 2EC7D4DDDB5FD85C5BAFCD176CF5C944A33F5FFD6052CD98EFC071E5186A96D0