Heap-based buffer overflow in adsmdll.dll 5.3.7.7296, as used by the daemon (dsmsvc.exe) in the backup server in IBM Tivoli Storage Manager (TSM) Express 5.3.7.3 and earlier and TSM 5.2, 5.3 before 5.3.6.0, and 5.4.0.0 through 5.4.4.0, allows remote attackers to execute arbitrary code via a crafted length value.
2009-03-11T14:19:15.187
2025-04-09T00:30:58.490
Deferred
CVSSv2: 10.0 (HIGH)
AV:N/AC:L/Au:N/C:C/I:C/A:C
10.0
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | microsoft | windows | * | No |
Application | ibm | tivoli_storage_manager | 5.2 | Yes |
Application | ibm | tivoli_storage_manager | 5.3 | Yes |
Application | ibm | tivoli_storage_manager | 5.3.0 | Yes |
Application | ibm | tivoli_storage_manager | 5.3.1 | Yes |
Application | ibm | tivoli_storage_manager | 5.3.2 | Yes |
Application | ibm | tivoli_storage_manager | 5.3.2.4 | Yes |
Application | ibm | tivoli_storage_manager | 5.3.3 | Yes |
Application | ibm | tivoli_storage_manager | 5.3.4 | Yes |
Application | ibm | tivoli_storage_manager | 5.3.5.1 | Yes |
Application | ibm | tivoli_storage_manager | 5.4.0 | Yes |
Application | ibm | tivoli_storage_manager | 5.4.1 | Yes |
Application | ibm | tivoli_storage_manager | 5.4.2 | Yes |
Application | ibm | tivoli_storage_manager | 5.4.2.2 | Yes |
Application | ibm | tivoli_storage_manager | 5.4.2.3 | Yes |
Application | ibm | tivoli_storage_manager | 5.4.2.4 | Yes |
Application | ibm | tivoli_storage_manager | 5.4.4.0 | Yes |
Application | ibm | tivoli_storage_manager_express | 5.3 | Yes |
Application | ibm | tivoli_storage_manager_express | 5.3.3.0 | Yes |
Application | ibm | tivoli_storage_manager_express | 5.3.6.4 | Yes |
Application | ibm | tivoli_storage_manager_express | 5.3.7.3 | Yes |