Lucene search

K
cveMitreCVE-2009-2754
HistoryMar 05, 2010 - 4:30 p.m.

CVE-2009-2754

2010-03-0516:30:00
CWE-189
mitre
web.nvd.nist.gov
23
cve-2009-2754
authentication functionality
librpc.dll
informix storage manager
ism portmapper service
portmap.exe
ibm informix dynamic server
ids 10.x
ids 11.x
emc legato networker
remote code execution
buffer overflow

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.7

Confidence

Low

EPSS

0.951

Percentile

99.4%

Integer signedness error in the authentication functionality in librpc.dll in the Informix Storage Manager (ISM) Portmapper service (aka portmap.exe), as used in IBM Informix Dynamic Server (IDS) 10.x before 10.00.TC9 and 11.x before 11.10.TC3 and EMC Legato NetWorker, allows remote attackers to execute arbitrary code via a crafted parameter size that triggers a stack-based buffer overflow.

Affected configurations

Nvd
Node
ibminformix_dynamic_serverMatch10.0
OR
ibminformix_dynamic_serverMatch10.0.tc1
OR
ibminformix_dynamic_serverMatch10.0.xc1
OR
ibminformix_dynamic_serverMatch10.0.xc2e
OR
ibminformix_dynamic_serverMatch10.0.xc3
OR
ibminformix_dynamic_serverMatch10.0.xc3e
OR
ibminformix_dynamic_serverMatch10.0.xc4
OR
ibminformix_dynamic_serverMatch10.0.xc4e
OR
ibminformix_dynamic_serverMatch10.0.xc5
OR
ibminformix_dynamic_serverMatch10.0.xc5e
OR
ibminformix_dynamic_serverMatch10.0.xc6
OR
ibminformix_dynamic_serverMatch10.0.xc6e
OR
ibminformix_dynamic_serverMatch10.0.xc7
OR
ibminformix_dynamic_serverMatch10.0.xc7e
OR
ibminformix_dynamic_serverMatch10.0.xc8
OR
ibminformix_dynamic_serverMatch10.0.xc8e
OR
ibminformix_dynamic_serverMatch10.0.xc9
OR
ibminformix_dynamic_serverMatch10.0.xc9e
OR
ibminformix_dynamic_serverMatch10.0.xc10
OR
ibminformix_dynamic_serverMatch10.0.xc10e
OR
ibminformix_dynamic_serverMatch11.1
OR
ibminformix_dynamic_serverMatch11.10
OR
ibminformix_dynamic_serverMatch11.10.xc1
OR
ibminformix_dynamic_serverMatch11.10.xc1de
OR
ibminformix_dynamic_serverMatch11.10.xc2
OR
ibminformix_dynamic_serverMatch11.10.xc2e
OR
ibminformix_dynamic_serverMatch11.10.xc3
OR
ibminformix_dynamic_serverMatch11.10.xc3e
Node
emclegato_networker
VendorProductVersionCPE
ibminformix_dynamic_server10.0cpe:2.3:a:ibm:informix_dynamic_server:10.0:*:*:*:*:*:*:*
ibminformix_dynamic_server10.0.tc1cpe:2.3:a:ibm:informix_dynamic_server:10.0.tc1:*:*:*:*:*:*:*
ibminformix_dynamic_server10.0.xc1cpe:2.3:a:ibm:informix_dynamic_server:10.0.xc1:*:*:*:*:*:*:*
ibminformix_dynamic_server10.0.xc2ecpe:2.3:a:ibm:informix_dynamic_server:10.0.xc2e:*:*:*:*:*:*:*
ibminformix_dynamic_server10.0.xc3cpe:2.3:a:ibm:informix_dynamic_server:10.0.xc3:*:*:*:*:*:*:*
ibminformix_dynamic_server10.0.xc3ecpe:2.3:a:ibm:informix_dynamic_server:10.0.xc3e:*:*:*:*:*:*:*
ibminformix_dynamic_server10.0.xc4cpe:2.3:a:ibm:informix_dynamic_server:10.0.xc4:*:*:*:*:*:*:*
ibminformix_dynamic_server10.0.xc4ecpe:2.3:a:ibm:informix_dynamic_server:10.0.xc4e:*:*:*:*:*:*:*
ibminformix_dynamic_server10.0.xc5cpe:2.3:a:ibm:informix_dynamic_server:10.0.xc5:*:*:*:*:*:*:*
ibminformix_dynamic_server10.0.xc5ecpe:2.3:a:ibm:informix_dynamic_server:10.0.xc5e:*:*:*:*:*:*:*
Rows per page:
1-10 of 291

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.7

Confidence

Low

EPSS

0.951

Percentile

99.4%