First published: Thu Oct 15 2009(Updated: )
Stack-based buffer overflow in libcsa.a (aka the calendar daemon library) in IBM AIX 5.x through 5.3.10 and 6.x through 6.1.3, and VIOS 2.1 and earlier, allows remote attackers to execute arbitrary code via a long XDR string in the first argument to procedure 21 of rpc.cmsd.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM AIX | =5.2.0.50 | |
IBM AIX | =5.3.8 | |
IBM AIX | =5.3.7 | |
IBM AIX | =5.3.0.20 | |
IBM AIX | =5.3_l | |
IBM AIX | =5l | |
IBM AIX | =6.1.3 | |
IBM AIX | =5.3.10 | |
IBM AIX | =5.3 | |
IBM AIX | =5 | |
IBM AIX | =6.1.0 | |
IBM Virtual I/O Server (VIOS) | <=2.1.0 | |
IBM AIX | =5.2 | |
IBM AIX | =6.1.1 | |
IBM AIX | =5.2_l | |
IBM AIX | =5.2.0.54 | |
IBM AIX | =6.1 | |
IBM AIX | =5.3_ml03 | |
IBM AIX | =5.3.9 | |
IBM Virtual I/O Server (VIOS) | =1.5.2 | |
IBM Virtual I/O Server (VIOS) | =1.4 | |
IBM AIX | =5.2.0 | |
IBM AIX | =5.2.2 | |
IBM Virtual I/O Server (VIOS) | =1.5.1 | |
IBM Virtual I/O Server (VIOS) | =1.5.0 | |
IBM AIX | =5.3-sp6 | |
IBM AIX | =5.1.0.10 | |
IBM AIX | =6.1.2 | |
IBM AIX | =5.1l | |
IBM AIX | =5.3.0 | |
IBM AIX | =5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-3699 has a critical severity rating due to its potential to allow remote attackers to execute arbitrary code.
To fix CVE-2009-3699, upgrade to an unaffected version of IBM AIX or apply the recommended patches provided by IBM.
CVE-2009-3699 affects IBM AIX versions 5.x through 5.3.10 and 6.x through 6.1.3, as well as VIOS 2.1 and earlier.
CVE-2009-3699 is a stack-based buffer overflow vulnerability in the calendar daemon library (libcsa.a).
Yes, CVE-2009-3699 can be exploited remotely through a long XDR string in a specific RPC procedure.