PT-2010-1273 · Ibm · Ibm Informix Dynamic Server

Sebastian Apelt

·

Publicado

2010-03-01

·

Atualizado

2018-10-10

·

CVE-2009-2754

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions IBM Informix Dynamic Server (IDS) versions 10.00.TC8 and earlier IBM Informix Dynamic Server (IDS) versions 11.10.TC2 and earlier
Description The issue is related to an integer signedness error in the authentication functionality of the librpc.dll component, used in the Informix Storage Manager (ISM) Portmapper service. This error can be exploited by remote attackers to execute arbitrary code via a crafted parameter size, triggering a stack-based buffer overflow.
Recommendations For IBM Informix Dynamic Server (IDS) versions 10.00.TC8 and earlier, update to version 10.00.TC9 or later. For IBM Informix Dynamic Server (IDS) versions 11.10.TC2 and earlier, update to version 11.10.TC3 or later.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2009-2754
ZDI-10-023

Produtos afetados

Ibm Informix Dynamic Server