Sploitus

CVE-2009-3699

5 known exploits for CVE-2009-3699

Stack-based buffer overflow in libcsa.a (aka the calendar daemon library) in IBM AIX 5.x through 5.3.10 and 6.x through 6.1.3, and VIOS 2.1 and earlier, allows remote attackers to execute arbitrary code via a long XDR string in the first argument to procedure 21 of rpc.cmsd.

Affected products
Ibm Aix, Vios, Libcsa.A
Ibm Vios
≤ 2.1.0, 1.4, 1.5.0, 1.5.1, 1.5.2
Ibm Aix
= 5, 5.1, 5.1.0.10, 5.1l, 5.2, 5.2.0, 5.2.0.50, 5.2.0.54, 5.2.2, 5.2_l, 5.3, 5.3.0, 5.3.0.20, 5.3.7, 5.3.8, 5.3.9, 5.3.10, 5.3_l, 5.3_ml03, 5l, 6.1, 6.1.0, 6.1.1, 6.1.2, 6.1.3
Fix
Available
CVSS 2.0
10.0 HIGH
EPSS
62.1% (99th percentile)
Weakness
CWE-119
NVD status
Modified
Published
2009-10-15
CVE-2009-3699 at NVD
Authoritative description, scoring and affected products

5 known exploits for CVE-2009-3699

Proof-of-concept code and exploit modules indexed by Sploitus