CVE-2009-2753: Buffer Overflow
Multiple buffer overflows in the authentication functionality in librpc.dll in the Informix Storage Manager (ISM) Portmapper service (aka portmap.exe), as used in IBM Informix Dynamic Server (IDS) 10.x before 10.00.TC9 and 11.x before 11.10.TC3, allow remote attackers to execute arbitrary code via a crafted parameter size.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-2753?
CVE-2009-2753 is rated as high severity due to its potential for remote code execution.
How do I fix CVE-2009-2753?
To fix CVE-2009-2753, apply the latest patches or updates provided by IBM for the affected versions of IBM Informix Dynamic Server.
Which versions of IBM Informix Dynamic Server are affected by CVE-2009-2753?
CVE-2009-2753 affects IBM Informix Dynamic Server versions 10.x before 10.00.TC9 and 11.x before 11.10.TC3.
What types of attacks are possible with CVE-2009-2753?
CVE-2009-2753 allows remote attackers to exploit buffer overflows leading to arbitrary code execution.
Is there a workaround for CVE-2009-2753?
While upgrading to a patched version is the best option, disabling the portmapper service can serve as a temporary workaround for CVE-2009-2753.