Integer Signedness Error in IBM Informix Dynamic Server and EMC Legato NetWorker
CVE-2009-2754
Currently unrated
Summary
The vulnerability arises from an integer signedness error in the authentication functionality of librpc.dll used by the Informix Storage Manager (ISM) Portmapper service. This flaw can allow remote attackers to execute arbitrary code by sending a specially crafted parameter that triggers a stack-based buffer overflow, posing a significant risk to the integrity and security of affected systems.
References
EPSS Score
36% chance of being exploited in the next 30 days.
Timeline
Vulnerability published
Vulnerability Reserved