IBM Informix Dynamic Server librpc.dll Multiple Buffer Overflows
| TSL ID | FSC20100301-08 |
| CVE ID(s) | CVE-2009-2753 |
| Severity | Critical |
| Description | A code execution vulnerability has been reported in IBM's Informix Dynamic Server. The vulnerability is due to insufficient validation of user input during authentication by the RPC protocol parsing library, librpc.dll. This library is used by the Portmapper service (portmap.exe) which runs on port TCP/36890. An attacker can exploit this vulnerability to cause heap and stack based buffer overflows which can lead to arbitrary code execution in the context of the affected service, which is SYSTEM. The vendor, IBM, has released advisories regarding this vulnerability which are available at: |
| Affected Products |
|
| CVSS Score |
Base 10.0 (AV:N/AC:L/Au:N/C:C/I:C/A:C):
|