CVE-2009-2727: Buffer Overflow
Stack-based buffer overflow in the ttinternalrealpath function in the ToolTalk library (libtt.a) in IBM AIX 5.2.0, 5.3.0, 5.3.7 through 5.3.10, and 6.1.0 through 6.1.3, when the rpc.ttdbserver daemon is enabled in /etc/inetd.conf, allows remote attackers to execute arbitrary code via a long XDR-encoded ASCII string to remote procedure 15.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-2727?
CVE-2009-2727 is rated as critical due to its potential to allow remote attackers to execute arbitrary code.
How do I fix CVE-2009-2727?
To fix CVE-2009-2727, you should apply the latest security patches provided by IBM for your AIX version.
What versions of AIX are affected by CVE-2009-2727?
CVE-2009-2727 affects IBM AIX versions 5.2.0, 5.3.0 to 5.3.10, and 6.1.0 to 6.1.3.
What is the impact of CVE-2009-2727?
The impact of CVE-2009-2727 can lead to remote code execution and compromise the affected system.
Is CVE-2009-2727 being actively exploited?
Yes, CVE-2009-2727 has been reported as actively exploited in the wild, heightening the urgency for mitigation.