Vulnerability record · CVE-2008-5177 · published 20 November 2008
CVE-2008-5177: Insight-tech yosemite backup memory buffer overflow vulnerability
Insight Tech · Yosemite Backup
Stack-based buffer overflow in the DtbClsLogin function in Yosemite Backup 8.7 allows remote attackers to (1) execute arbitrary code on a Linux platform, related to libytlindtb.so; or (2) cause a denial of service (application crash) and possibly execute arbitrary code on a Windows platform, related to ytwindtb.dll; via a long username field during authentication.
Description
Stack-based buffer overflow in the DtbClsLogin function in Yosemite Backup 8.7 allows remote attackers to (1) execute arbitrary code on a Linux platform, related to libytlindtb.so; or (2) cause a denial of service (application crash) and possibly execute arbitrary code on a Windows platform, related to ytwindtb.dll; via a long username field during authentication.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://osvdb.org/49743 | |
| http://osvdb.org/49744 | |
| http://secunia.com/advisories/32262 | Vendor Advisory |
| http://www.insight-tech.org/index.php?p=Yosemite-backup-8-7-DtbClsLogin-Buffer-Overflow-Vulnerability | ExploitVendor AdvisoryURL Repurposed |
| http://www.insight-tech.org/xploits/yosemiteStackOverflowExploit.zip | ExploitURL Repurposed |
| http://www.securityfocus.com/bid/32246 | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/46515 | |
| http://osvdb.org/49743 | |
| http://osvdb.org/49744 | |
| http://secunia.com/advisories/32262 | Vendor Advisory |
| http://www.insight-tech.org/index.php?p=Yosemite-backup-8-7-DtbClsLogin-Buffer-Overflow-Vulnerability | ExploitVendor AdvisoryURL Repurposed |
| http://www.insight-tech.org/xploits/yosemiteStackOverflowExploit.zip | ExploitURL Repurposed |
| http://www.securityfocus.com/bid/32246 | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/46515 |
Track CVE-2008-5177 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2008-5177), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.