IBM Informix Products Setnet32 Utility '.nfx' File Buffer Overflow Vulnerability
BID:36588
Info
IBM Informix Products Setnet32 Utility '.nfx' File Buffer Overflow Vulnerability
| Bugtraq ID: | 36588 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 01 2009 12:00AM |
| Updated: | Oct 15 2009 10:28PM |
| Credit: | Nine:Situations:Group::bruiser |
| Vulnerable: |
IBM Informix CSDK 3.50 IBM Informix Connect 3.0 |
| Not Vulnerable: | |
Discussion
IBM Informix Products Setnet32 Utility '.nfx' File Buffer Overflow Vulnerability
Multiple IBM Informix products are prone to a buffer-overflow vulnerability because the software fails to bounds-check user-supplied data before copying it into an insufficiently sized buffer.
An attacker can exploit this issue to execute arbitrary code within the context of the affected application. Failed exploit attempts will result in a denial-of-service condition.
This issue affects the following:
IBM Informix Client Software Development Kit (CSDK) 3.5
IBM Informix Connect 3.x
Other products that use the Setnet32 3.50.0.13752 utility may also be vulnerable.
Multiple IBM Informix products are prone to a buffer-overflow vulnerability because the software fails to bounds-check user-supplied data before copying it into an insufficiently sized buffer.
An attacker can exploit this issue to execute arbitrary code within the context of the affected application. Failed exploit attempts will result in a denial-of-service condition.
This issue affects the following:
IBM Informix Client Software Development Kit (CSDK) 3.5
IBM Informix Connect 3.x
Other products that use the Setnet32 3.50.0.13752 utility may also be vulnerable.
Exploit / POC
IBM Informix Products Setnet32 Utility '.nfx' File Buffer Overflow Vulnerability
A working commercial exploit is available through VUPEN Security - Exploit and PoCs Service. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following exploit code is available:
A working commercial exploit is available through VUPEN Security - Exploit and PoCs Service. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following exploit code is available:
Solution / Fix
IBM Informix Products Setnet32 Utility '.nfx' File Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
IBM Informix Products Setnet32 Utility '.nfx' File Buffer Overflow Vulnerability
References:
References: