CVE-2009-3699
Summary
| CVE | CVE-2009-3699 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2009-10-15 10:30:01 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Stack-based buffer overflow in libcsa.a (aka the calendar daemon library) in IBM AIX 5.x through 5.3.10 and 6.x through 6.1.3, and VIOS 2.1 and earlier, allows remote attackers to execute arbitrary code via a long XDR string in the first argument to procedure 21 of rpc.cmsd. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Ibm | Aix | 5 | All | All | All |
| Operating System | Ibm | Aix | 5.1 | All | All | All |
| Operating System | Ibm | Aix | 5.1.0.10 | All | All | All |
| Operating System | Ibm | Aix | 5.1l | All | All | All |
| Operating System | Ibm | Aix | 5.2 | All | All | All |
| Operating System | Ibm | Aix | 5.2.0 | All | All | All |
| Operating System | Ibm | Aix | 5.2.0.50 | All | All | All |
| Operating System | Ibm | Aix | 5.2.0.54 | All | All | All |
| Operating System | Ibm | Aix | 5.2.2 | All | All | All |
| Operating System | Ibm | Aix | 5.2_l | All | All | All |
| Operating System | Ibm | Aix | 5.3 | All | All | All |
| Operating System | Ibm | Aix | 5.3 | sp6 | All | All |
| Operating System | Ibm | Aix | 5.3.0 | All | All | All |
| Operating System | Ibm | Aix | 5.3.0.20 | All | All | All |
| Operating System | Ibm | Aix | 5.3.10 | All | All | All |
| Operating System | Ibm | Aix | 5.3.7 | All | All | All |
| Operating System | Ibm | Aix | 5.3.8 | All | All | All |
| Operating System | Ibm | Aix | 5.3.9 | All | All | All |
| Operating System | Ibm | Aix | 5.3_l | All | All | All |
| Operating System | Ibm | Aix | 5.3_ml03 | All | All | All |
| Operating System | Ibm | Aix | 5l | All | All | All |
| Operating System | Ibm | Aix | 6.1 | All | All | All |
| Operating System | Ibm | Aix | 6.1.0 | All | All | All |
| Operating System | Ibm | Aix | 6.1.1 | All | All | All |
| Operating System | Ibm | Aix | 6.1.2 | All | All | All |
| Operating System | Ibm | Aix | 6.1.3 | All | All | All |
| Application | Ibm | Vios | 1.4 | All | All | All |
| Application | Ibm | Vios | 1.5.0 | All | All | All |
| Application | Ibm | Vios | 1.5.1 | All | All | All |
| Application | Ibm | Vios | 1.5.2 | All | All | All |
| Application | Ibm | Vios | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM notice: The page you requested cannot be displayed | af854a3a-2127-422b-91ae-364da2661108 | www.ibm.com | Vendor Advisory |
| IBM notice: The page you requested cannot be displayed | af854a3a-2127-422b-91ae-364da2661108 | www.ibm.com | |
| IBM notice: The page you requested cannot be displayed | af854a3a-2127-422b-91ae-364da2661108 | www.ibm.com | |
| IBM AIX 'rpc.cmsd' Calendar Daemon Remote Stack Buffer Overflow Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Exploit, Patch |
| IBM notice: The page you requested cannot be displayed | af854a3a-2127-422b-91ae-364da2661108 | www.ibm.com | |
| IBM notice: The page you requested cannot be displayed | af854a3a-2127-422b-91ae-364da2661108 | www.ibm.com | |
| IBM notice: The page you requested cannot be displayed | af854a3a-2127-422b-91ae-364da2661108 | www.ibm.com | |
| labs.idefense.com/intelligence/vulnerabilities/display.php | af854a3a-2127-422b-91ae-364da2661108 | labs.idefense.com | Patch |
| SecurityTracker.com Archives - IBM AIX Buffer Overflow in 'rpc.cmsd' Lets Remote Users Obtain Root Privileges | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| IBM notice: The page you requested cannot be displayed | af854a3a-2127-422b-91ae-364da2661108 | www.ibm.com | |
| IBM AIX rpc.cmsd Buffer Overflow Vulnerability - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Patch, Vendor Advisory |
| www.osvdb.org/58726 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| aix.software.ibm.com/aix/efixes/security/cmsd_advisory.asc | af854a3a-2127-422b-91ae-364da2661108 | aix.software.ibm.com | Vendor Advisory |
| IBM notice: The page you requested cannot be displayed | af854a3a-2127-422b-91ae-364da2661108 | www.ibm.com | |
| IBM notice: The page you requested cannot be displayed | af854a3a-2127-422b-91ae-364da2661108 | www.ibm.com | |
| 404 Not Found | af854a3a-2127-422b-91ae-364da2661108 | www.immunityinc.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.