Vulnerability Description
Heap-based buffer overflow in the tvtumin.sys kernel driver in Lenovo Rescue and Recovery 4.20, including 4.20.0511 and 4.20.0512, allows local users to execute arbitrary code via a long file name.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Lenovo | Resuce And Recovery | 4.20 |
Related Weaknesses (CWE)
References
- http://secunia.com/advisories/32252Vendor Advisory
- http://securityreason.com/securityalert/4421
- http://www-307.ibm.com/pc/support/site.wss/MIGR-4Q2QAK.htmlPatchVendor Advisory
- http://www-307.ibm.com/pc/support/site.wss/MIGR-70699.htmlPatchVendor Advisory
- http://www.isecpartners.com/advisories/2008-02-lenovornr.txt
- http://www.securityfocus.com/archive/1/497277/100/0/threaded
- http://www.securityfocus.com/bid/31737Patch
- http://www.securitytracker.com/id?1021041
- http://www.vupen.com/english/advisories/2008/2806
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45839
- http://secunia.com/advisories/32252Vendor Advisory
- http://securityreason.com/securityalert/4421
- http://www-307.ibm.com/pc/support/site.wss/MIGR-4Q2QAK.htmlPatchVendor Advisory
- http://www-307.ibm.com/pc/support/site.wss/MIGR-70699.htmlPatchVendor Advisory
- http://www.isecpartners.com/advisories/2008-02-lenovornr.txt
FAQ
What is CVE-2008-4589?
CVE-2008-4589 is a vulnerability with a CVSS score of 7.2 (HIGH). Heap-based buffer overflow in the tvtumin.sys kernel driver in Lenovo Rescue and Recovery 4.20, including 4.20.0511 and 4.20.0512, allows local users to execute arbitrary code via a long file name.
How severe is CVE-2008-4589?
CVE-2008-4589 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2008-4589?
Check the references section above for vendor advisories and patch information. Affected products include: Lenovo Resuce And Recovery.