Integer Signedness Error in IBM Informix Dynamic Server and EMC Legato NetWorker
CVE-2009-2754

Currently unrated

Key Information:

Vendor
IBM
Vendor
CVE Published:
5 March 2010

Summary

The vulnerability arises from an integer signedness error in the authentication functionality of librpc.dll used by the Informix Storage Manager (ISM) Portmapper service. This flaw can allow remote attackers to execute arbitrary code by sending a specially crafted parameter that triggers a stack-based buffer overflow, posing a significant risk to the integrity and security of affected systems.

References

EPSS Score

36% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.