CVE-2009-3699: Buffer Overflow
Stack-based buffer overflow in libcsa.a (aka the calendar daemon library) in IBM AIX 5.x through 5.3.10 and 6.x through 6.1.3, and VIOS 2.1 and earlier, allows remote attackers to execute arbitrary code via a long XDR string in the first argument to procedure 21 of rpc.cmsd.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-3699?
CVE-2009-3699 has a critical severity rating due to its potential to allow remote attackers to execute arbitrary code.
How do I fix CVE-2009-3699?
To fix CVE-2009-3699, upgrade to an unaffected version of IBM AIX or apply the recommended patches provided by IBM.
What systems are affected by CVE-2009-3699?
CVE-2009-3699 affects IBM AIX versions 5.x through 5.3.10 and 6.x through 6.1.3, as well as VIOS 2.1 and earlier.
What type of vulnerability is CVE-2009-3699?
CVE-2009-3699 is a stack-based buffer overflow vulnerability in the calendar daemon library (libcsa.a).
Can CVE-2009-3699 be exploited remotely?
Yes, CVE-2009-3699 can be exploited remotely through a long XDR string in a specific RPC procedure.