Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2009-2754


Integer signedness error in the authentication functionality in librpc.dll in the Informix Storage Manager (ISM) Portmapper service (aka portmap.exe), as used in IBM Informix Dynamic Server (IDS) 10.x before 10.00.TC9 and 11.x before 11.10.TC3 and EMC Legato NetWorker, allows remote attackers to execute arbitrary code via a crafted parameter size that triggers a stack-based buffer overflow.


Published

2010-03-05T16:30:00.583

Last Modified

2025-04-11T00:51:21.963

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 10.0 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:C/I:C/A:C

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

10.0

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-189

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application ibm informix_dynamic_server 10.0 Yes
Application ibm informix_dynamic_server 10.0.tc1 Yes
Application ibm informix_dynamic_server 10.0.xc1 Yes
Application ibm informix_dynamic_server 10.0.xc2e Yes
Application ibm informix_dynamic_server 10.0.xc3 Yes
Application ibm informix_dynamic_server 10.0.xc3e Yes
Application ibm informix_dynamic_server 10.0.xc4 Yes
Application ibm informix_dynamic_server 10.0.xc4e Yes
Application ibm informix_dynamic_server 10.0.xc5 Yes
Application ibm informix_dynamic_server 10.0.xc5e Yes
Application ibm informix_dynamic_server 10.0.xc6 Yes
Application ibm informix_dynamic_server 10.0.xc6e Yes
Application ibm informix_dynamic_server 10.0.xc7 Yes
Application ibm informix_dynamic_server 10.0.xc7e Yes
Application ibm informix_dynamic_server 10.0.xc8 Yes
Application ibm informix_dynamic_server 10.0.xc8e Yes
Application ibm informix_dynamic_server 10.0.xc9 Yes
Application ibm informix_dynamic_server 10.0.xc9e Yes
Application ibm informix_dynamic_server 10.0.xc10 Yes
Application ibm informix_dynamic_server 10.0.xc10e Yes
Application ibm informix_dynamic_server 11.1 Yes
Application ibm informix_dynamic_server 11.10 Yes
Application ibm informix_dynamic_server 11.10.xc1 Yes
Application ibm informix_dynamic_server 11.10.xc1de Yes
Application ibm informix_dynamic_server 11.10.xc2 Yes
Application ibm informix_dynamic_server 11.10.xc2e Yes
Application ibm informix_dynamic_server 11.10.xc3 Yes
Application ibm informix_dynamic_server 11.10.xc3e Yes
Application emc legato_networker * Yes

References