Check Point Reference: | CPAI-2011-101 |
Date Published: | 28 Feb 2011 |
Severity: | High |
Last Updated: | Saturday 01 January, 2011 |
Source: | Secunia Advisory SA38731 |
Industry Reference: | CVE-2009-2754 |
Protection Provided by: | |
Who is Vulnerable? | EMC Legato NetWorker IBM Informix Dynamic Server prior to 10.00.TC9 IBM Informix Dynamic Server prior to 11.10.TC3 |
Vulnerability Description | A buffer overflow vulnerability exists in IBM's Informix Dynamic Server and EMC's Legato Networker. The vulnerability is due to insufficient validation of user input during authentication by the RPC protocol parsing library, librpc.dll, used by the Portmapper service (portmap.exe). Successful exploitation may result in arbitrary code execution on the affected system. |
Vulnerability Details | The vulnerability is due to improper bounds checking of the Machine Name parameter in the AUTH_UNIX flavour of the remote procedure call authentication. |