CVE-2009-2754

CVSS 10.0 - HIGH
Description

Integer signedness error in the authentication functionality in librpc.dll in the Informix Storage Manager (ISM) Portmapper service (aka portmap.exe), as used in IBM Informix Dynamic Server (IDS) 10.x before 10.00.TC9 and 11.x before 11.10.TC3 and EMC Legato NetWorker, allows remote attackers to execute arbitrary code via a crafted parameter size that triggers a stack-based buffer overflow.

Affected Products
29
Vendor Product Version
ibm informix_dynamic_server 10.0
ibm informix_dynamic_server 10.0.tc1
ibm informix_dynamic_server 10.0.xc1
ibm informix_dynamic_server 10.0.xc2e
ibm informix_dynamic_server 10.0.xc3
ibm informix_dynamic_server 10.0.xc3e
ibm informix_dynamic_server 10.0.xc4
ibm informix_dynamic_server 10.0.xc4e
ibm informix_dynamic_server 10.0.xc5
ibm informix_dynamic_server 10.0.xc5e
ibm informix_dynamic_server 10.0.xc6
ibm informix_dynamic_server 10.0.xc6e
ibm informix_dynamic_server 10.0.xc7
ibm informix_dynamic_server 10.0.xc7e
ibm informix_dynamic_server 10.0.xc8
ibm informix_dynamic_server 10.0.xc8e
ibm informix_dynamic_server 10.0.xc9
ibm informix_dynamic_server 10.0.xc9e
ibm informix_dynamic_server 10.0.xc10
ibm informix_dynamic_server 10.0.xc10e
ibm informix_dynamic_server 11.1
ibm informix_dynamic_server 11.10
ibm informix_dynamic_server 11.10.xc1
ibm informix_dynamic_server 11.10.xc1de
ibm informix_dynamic_server 11.10.xc2
ibm informix_dynamic_server 11.10.xc2e
ibm informix_dynamic_server 11.10.xc3
ibm informix_dynamic_server 11.10.xc3e
emc legato_networker All versions
Weakness Types
CWE-189
CVE Information
CVE ID:
CVE-2009-2754
Published:
2010-03-05
Modified:
2026-04-29
CVSS Score:
10.0
Severity:
HIGH
Vector:
AV:N/AC:L/Au:N/C:C/I:C/A:C
Affected Vendors
ibm emc
Quick Actions
CVSS Severity Scale
0.0 - 3.9 LOW
4.0 - 6.9 MEDIUM
7.0 - 8.9 HIGH
9.0 - 10.0 CRITICAL