Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

This site is deprecated. Please CLICK HERE for latest updates

Short Name

APP:IBM:TIVOLI-FASTBACK-OP-BO

Severity

Major

Recommended

Yes

Recommended Action

Drop

Category

APP

Keywords

IBM Tivoli Storage Manager FastBack Server Opcode 1332 Buffer Overflow

Release Date

2015/11/19

Update Number

2569

Supported Platforms

idp-4.0+, isg-3.0+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+

APP: IBM Tivoli Storage Manager FastBack Server Opcode 1332 Buffer Overflow


A buffer overflow vulnerability exists in IBM Tivoli Storage Manager FastBack Server. The vulnerability is due to insufficient boundary checking on parameters in opcode 1332 requests. A remote unauthenticated attacker could exploit this vulnerability by sending crafted requests to port 11460/TCP. Successful exploitation results in arbitrary code execution within the context of System.

Extended Description

Stack-based buffer overflow in the server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors, a different vulnerability than CVE-2015-1924, CVE-2015-1929, CVE-2015-1930, CVE-2015-1948, CVE-2015-1953, CVE-2015-1954, CVE-2015-1962, CVE-2015-1963, CVE-2015-1964, and CVE-2015-1965.

Affected Products

  • Ibm tivoli_storage_manager_fastback 6.1.0.0
  • Ibm tivoli_storage_manager_fastback 6.1.1.0
  • Ibm tivoli_storage_manager_fastback 6.1.10.0
  • Ibm tivoli_storage_manager_fastback 6.1.10.1
  • Ibm tivoli_storage_manager_fastback 6.1.11.0
  • Ibm tivoli_storage_manager_fastback 6.1.11.1
  • Ibm tivoli_storage_manager_fastback 6.1.7.2
  • Ibm tivoli_storage_manager_fastback 6.1.8.0
  • Ibm tivoli_storage_manager_fastback 6.1.8.1
  • Ibm tivoli_storage_manager_fastback 6.1.9.0
  • Ibm tivoli_storage_manager_fastback 6.1.9.1

References

  • BugTraq: 75449
  • CVE: CVE-2015-1925
  • URL: http://www-01.ibm.com/support/docview.wss?uid=swg21959398
  • URL: http://www.zerodayinitiative.com/advisories/ZDI-15-266/

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out