vendor:
Informix Dynamic Server
by:
ZSploit.com
7,5
CVSS
HIGH
Signedness Error Remote Code Execution
190
CWE
Product Name: Informix Dynamic Server
Affected Version From: IBM Informix Dynamic Server 10.0
Affected Version To: IBM Informix Dynamic Server 10.0
Patch Exists: YES
Related CWE: CVE-2009-2754
CPE: a:ibm:informix_dynamic_server:10.0
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2010
ZDI-10-023: Multiple Vendor librpc.dll Signedness Error Remote Code Execution Vulnerability
The issue in __lgto_svcauth_unix() is a signedness error, where if a user-supplied size is given, it can cause a stack overflow.
Mitigation:
Ensure that user-supplied sizes are properly validated before being used in memory operations.