CVE-2009-3699

EUVD-2009-3672
Stack-based buffer overflow in libcsa.a (aka the calendar daemon library) in IBM AIX 5.x through 5.3.10 and 6.x through 6.1.3, and VIOS 2.1 and earlier, allows remote attackers to execute arbitrary code via a long XDR string in the first argument to procedure 21 of rpc.cmsd.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
10 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:C/I:C/A:C
Base Score
CVSS 3.x
EPSS Score
Percentile: 99%
Affected Products (NVD)
VendorProductVersion
ibmvios
𝑥
≤ 2.1.0
ibmvios
1.4
ibmvios
1.5.0
ibmvios
1.5.1
ibmvios
1.5.2
ibmaix
5.1
ibmaix
5.1.0.10
ibmaix
5.1l:l
ibmaix
5.2
ibmaix
5.2.0
ibmaix
5.2.0.50
ibmaix
5.2.0.54
ibmaix
5.2.2
ibmaix
5.2_l:_l
ibmaix
5.3
ibmaix
5.3:sp6
ibmaix
5.3.0
ibmaix
5.3.0.20
ibmaix
5.3.7
ibmaix
5.3.8
ibmaix
5.3.9
ibmaix
5.3.10
ibmaix
5.3_l:_l
ibmaix
5.3_ml03:_ml03
ibmaix
6.1
ibmaix
6.1.0
ibmaix
6.1.1
ibmaix
6.1.2
ibmaix
6.1.3
𝑥
= Vulnerable software versions
References