Check Point Reference: | CPAI-2010-121 |
Date Published: | 23 Apr 2010 |
Severity: | Critical |
Last Updated: | Friday 01 January, 2010 |
Source: | Secunia Advisory: SA38731 |
Industry Reference: | CVE-2009-2754 |
Protection Provided by: | |
Who is Vulnerable? | EMC Legato NetWorker 7.x.x
IBM Informix Dynamic Server prior to 10.00.TC9 |
Vulnerability Description | A buffer overflow vulnerability exists in IBM's Informix Dynamic Server and EMC's Legato Networker. Informix is a family of relational database management system (RDBMS) products by IBM. The vulnerability is due to insufficient validation of user input during authentication by the RPC protocol parsing library. An attacker can exploit this vulnerability to cause stack based buffer overflow which can lead to arbitrary code execution on the affected system. |
Update/Patch Avaliable | At the time of writing, the vendor has not released an advisory addressing this vulnerability. |
Vulnerability Details | A stack buffer overflow vulnerability exists in RPC library of IBM Informix port mapper module, librpc.dll. The vulnerability is due to improper bounds checking of the remote procedure call authentication. |