PT-2021-18397 · Ibm · Ibm Spectrum Protect Client
Published
2021-04-26
·
Updated
2022-09-30
·
CVE-2021-29672
CVSS v3.1
8.4
High
| Vector | AC:L/C:H/PR:N/AV:L/UI:N/I:H/S:U/A:H |
Name of the Vulnerable Software and Affected Versions
IBM Spectrum Protect Client versions 8.1.0.0-8 through 1.11.0
Description
The issue is caused by improper bounds checking when processing the current locale settings, leading to a stack-based buffer overflow. A local attacker could overflow a buffer and execute arbitrary code on the system with elevated privileges or cause the application to crash.
Recommendations
For IBM Spectrum Protect Client versions 8.1.0.0-8 through 1.11.0, update to a version that includes the fix for the improper bounds checking issue.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Spectrum Protect Client